
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-46862 is a Denial of Service vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). It affects MySQL Router versions 8.4.0–8.4.9 and 9.0.0–9.7.0, allowing an unauthenticated remote attacker with network access via TLS to cause a hang or frequently repeatable crash of the service. The vulnerability was disclosed on June 16, 2026, as part of Oracle's Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 7.5 (High) (Oracle Advisory).
The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption), indicating that MySQL Router fails to properly limit resource usage when processing certain TLS-based network requests. An unauthenticated attacker can send crafted TLS traffic to a vulnerable MySQL Router instance, triggering a hang or crash without requiring any credentials or user interaction. The attack complexity is low and the vulnerability is considered automatable, meaning it can be reliably triggered at scale. The vulnerability was reported to Oracle by Asim Viladi Oglu Manizada (Oracle Advisory).
Successful exploitation results in complete unavailability of the MySQL Router service — either through a persistent hang or a frequently repeatable crash — constituting a full Denial of Service. There is no confidentiality or integrity impact; the vulnerability is limited to availability. Because MySQL Router acts as a middleware routing layer for MySQL database connections, its disruption can cascade to dependent applications and database clusters, potentially causing broader service outages (Oracle Advisory).
Oracle released patches for this vulnerability on June 16, 2026, as part of the June 2026 Critical Security Patch Update. Users should upgrade MySQL Router to a version beyond 8.4.9 (in the 8.4.x line) or beyond 9.7.0 (in the 9.x line) as provided by Oracle. As a temporary workaround, administrators should implement network-level access controls (e.g., firewall rules) to restrict TLS connections to MySQL Router to trusted clients only, and configure automated restart mechanisms to minimize downtime in the event of a crash. Oracle strongly recommends applying the patch without delay (Oracle Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."