CVE-2026-46862
MySQL vulnerability analysis and mitigation

Overview

CVE-2026-46862 is a Denial of Service vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). It affects MySQL Router versions 8.4.0–8.4.9 and 9.0.0–9.7.0, allowing an unauthenticated remote attacker with network access via TLS to cause a hang or frequently repeatable crash of the service. The vulnerability was disclosed on June 16, 2026, as part of Oracle's Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 7.5 (High) (Oracle Advisory).

Technical details

The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption), indicating that MySQL Router fails to properly limit resource usage when processing certain TLS-based network requests. An unauthenticated attacker can send crafted TLS traffic to a vulnerable MySQL Router instance, triggering a hang or crash without requiring any credentials or user interaction. The attack complexity is low and the vulnerability is considered automatable, meaning it can be reliably triggered at scale. The vulnerability was reported to Oracle by Asim Viladi Oglu Manizada (Oracle Advisory).

Impact

Successful exploitation results in complete unavailability of the MySQL Router service — either through a persistent hang or a frequently repeatable crash — constituting a full Denial of Service. There is no confidentiality or integrity impact; the vulnerability is limited to availability. Because MySQL Router acts as a middleware routing layer for MySQL database connections, its disruption can cascade to dependent applications and database clusters, potentially causing broader service outages (Oracle Advisory).

Indicators of compromise

  • Network: Unusual or high-volume TLS connection attempts to MySQL Router listener ports (default: 6446, 6447, 64460, 64470) from unexpected or untrusted source IPs.
  • Logs: MySQL Router logs showing repeated crashes, restarts, or unhandled exceptions in the Router: General component; error entries indicating resource exhaustion or abnormal TLS handshake failures.
  • Process: MySQL Router process repeatedly terminating and restarting (if auto-restart is configured); elevated CPU or memory usage by the mysqlrouter process prior to crash.

Mitigation and workarounds

Oracle released patches for this vulnerability on June 16, 2026, as part of the June 2026 Critical Security Patch Update. Users should upgrade MySQL Router to a version beyond 8.4.9 (in the 8.4.x line) or beyond 9.7.0 (in the 9.x line) as provided by Oracle. As a temporary workaround, administrators should implement network-level access controls (e.g., firewall rules) to restrict TLS connections to MySQL Router to trusted clients only, and configure automated restart mechanisms to minimize downtime in the event of a crash. Oracle strongly recommends applying the patch without delay (Oracle Advisory).

Additional resources


SourceThis report was generated using AI

Related MySQL vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61109MEDIUM6.5
  • MySQL logoMySQL
  • cpe:2.3:a:oracle:mysql_cluster
NoYesJul 21, 2026
CVE-2026-61108MEDIUM6.5
  • MySQL logoMySQL
  • cpe:2.3:a:oracle:mysql_server
NoNoJul 21, 2026
CVE-2026-61144MEDIUM4.9
  • MySQL logoMySQL
  • cpe:2.3:a:oracle:mysql_cluster
NoNoJul 21, 2026
CVE-2026-61128MEDIUM4.9
  • MySQL logoMySQL
  • cpe:2.3:a:oracle:mysql_server
NoNoJul 21, 2026
CVE-2026-61096LOW2.9
  • MySQL logoMySQL
  • cpe:2.3:a:oracle:mysql_server
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management