CVE-2026-34318: Infoleak
Last updated 6 June 2026
Other sources
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Shell. While the vulnerability is in MySQL Shell, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Shell accessible data. CVSS 3.1 Base Score 5.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N).
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34318?
The severity of CVE-2026-34318 is categorized as difficult to exploit but allows high privileged attackers to compromise affected systems.
How do I fix CVE-2026-34318?
To fix CVE-2026-34318, update your MySQL Shell to a version that is not vulnerable, specifically 8.0.46 and later, 8.4.9 and later, or 9.6.1 and later.
What versions of MySQL Shell are affected by CVE-2026-34318?
CVE-2026-34318 affects MySQL Shell versions 8.0.0-8.0.45, 8.4.0-8.4.8, and 9.0.0-9.6.0.
What types of access are required to exploit CVE-2026-34318?
CVE-2026-34318 can be exploited by high privileged attackers with network access via multiple protocols.
Is CVE-2026-34318 specific to a certain product?
Yes, CVE-2026-34318 specifically affects the MySQL Shell product of Oracle MySQL.