CVE-2026-46850: Remote Code Execution via Code Injection in MySQL Shell for VS Code
HERMES THREAT SCORE & OPERATIONAL EXPOSURE
Target:MySQL Shell (Shell for VS Code) — Oracle MySQL Enterprise & Community Ecosystem While CVSS rates CVE-2026-46850 at 9.9, Hermes scores this flaw at 94 (CRITICAL). The combination of network accessibility over HTTP RPC bridges, low required privileges, and Scope Change (S:C) allows unprivileged database operators to execute arbitrary commands on developer workstations, pillaging cloud credentials, source code, and deployment pipeline secrets.
HASS INFRASTRUCTURE & AGENTIC IMPACT POSTURE
Target:Developer Workstations, IDE Workspaces & Automated CI/CD Agents Modern automated database deployment pipelines, agentic query tooling, and Kubernetes operators rely on reliable boundaries. Compromising MySQL Shell (Shell for VS Code) allows adversaries to pierce compartmentalization boundaries and expand footholds across adjacent infrastructure.
CVE-2026-46850: Remote Code Execution via Code Injection in MySQL Shell for VS CodeVULNERABILITY
Software platform affected by security vulnerabilities and agentic attack patterns.
🔍 Why is this related? (Evidence & Provenance)
“Confirmed security vulnerability in Oracle MySQL Shell & VS Code Extension documented in Hermes dossier.”
- [vulnerability_report]
- [government_confirmation]CISA verified active exploitation in the wild and mandated federal remediation deadline in KEV entry. — Source: Cybersecurity & Infrastructure Security Agency (CISA): CISA Adds CVE-2026-59822 to Known Exploited Vulnerabilities Catalog (Reliability: VERY_HIGH)
1. Technical Context & Affected Software Matrix
Section titled “1. Technical Context & Affected Software Matrix”MySQL Shell (Shell for VS Code) plays a central role within the Oracle MySQL ecosystem. Flaws in this layer expose both database assets and interconnecting applications.
| Parameter | Technical Specification | Operational Context |
|---|---|---|
| CVE Identifier | CVE-2026-46850 | Oracle CPU Record / NVD Reference |
| Component Name | MySQL Shell (Shell for VS Code) | Oracle MySQL Ecosystem |
| Vulnerability Class | Code Injection & Workstation Escaping | CWE-94 (Improper Control of Generation of Code (‘Code Injection’)) |
| Network Vector | TCP 4300-4350 (Internal Shell RPC) / HTTP | Low Privileged Network Access |
| Scope Impact | Scope Change (S:C) — Host/Cluster Escaping | Impact across trust boundaries |
| Affected Versions | MySQL Shell 2026.2.0+9.6.1 and prior releases | Prior releases lacking patch validation |
| Fixed Releases | 2026.2.1+9.6.2 | Available in official Oracle distribution |
2. Root Cause Analysis & Architectural Flaw
Section titled “2. Root Cause Analysis & Architectural Flaw”Flaw Mechanism in MySQL Shell (Shell for VS Code)
Section titled “Flaw Mechanism in MySQL Shell (Shell for VS Code)”The vulnerability originates from insufficient input sanitization, improper access control, or incorrect privilege delegation within MySQL Shell (Shell for VS Code).
+-------------------------------------------------------------------------+| ATTACK INGRESS || Attacker / Rogue Client ==[ AV:N ]==> MySQL Shell (Shell for VS Code) |+-------------------------------------------------------------------------+ | v+-------------------------------------------------------------------------+| VULNERABILITY EXECUTION BOUNDARY || - Parsing & Verification Defect: CWE-94 (Improper Control of Generation of Code ('Code Injection')) || - Security Boundary Failure: Breaks out into Host OS / Kubernetes |+-------------------------------------------------------------------------+ | v+-------------------------------------------------------------------------+| IMPACTED ASSETS || - Confidentiality: Full Host / DB Read || - Integrity: Arbitrary State Manipulation || - Availability: Full Denial of Service / Crash |+-------------------------------------------------------------------------+When receiving requests over TCP 4300-4350 (Internal Shell RPC) / HTTP, the component fails to enforce strict boundary restrictions. An attacker capitalizing on this logic gap can manipulate execution state, invoke privileged RPC endpoints, or crash daemon routines.
3. Attack Chain & Weaponization Flow
Section titled “3. Attack Chain & Weaponization Flow”sequenceDiagram autonumber actor Attacker as Attacker / Compromised Client participant Target as MySQL Shell (Shell for VS Code) participant Backend as Core Database / Host Runtime
Attacker->>Target: Transmit crafted payload over TCP 4300-4350 (Internal Shell RPC) / HTTP Note over Target: Trigger logic bug: CWE-94 Target->>Backend: Execute unauthorized action / Unvalidated RPC Note over Backend: Scope Change triggered: Host breakout Backend-->>Attacker: Administrative access / Intercepted credentials / Denial of Service4. Forensic Triage & Detection Engineering
Section titled “4. Forensic Triage & Detection Engineering”title: Suspicious Activity Related to CVE-2026-46850 in MySQL Shell (Shell for VS Code)id: cve-2026-46850-detection-sigmastatus: experimentaldescription: Detects suspicious process lineage or abnormal command execution related to CVE-2026-46850.references: - https://www.oracle.com/security-alerts/author: Hermes Codex Cyber Intelligencedate: 2026-09-15tags: - attack.initial_access - attack.execution - attack.t1190logsource: category: process_creation product: linuxdetection: selection_parent: ParentImage|endswith: - 'code' selection_child: Image|endswith: - '/bin/bash' condition: selection_parent and selection_childlevel: high# Suricata / Network IDS inspection signaturealert tcp any any -> any any (msg:"HERMES - Potential CVE-2026-46850 Exploitation Pattern in MySQL Shell (Shell for VS Code)"; flow:to_server,established; content:"MySQL"; nocase; threshold:type limit, track by_src, count 5, seconds 60; classtype:attempted-admin; sid:46850; rev:1;)# Verify running version of MySQL Shell (Shell for VS Code)mysql --version || mysqlrouter --version || mysqlsh --version
# Check for abnormal child processes spawned by database daemonsps -ef | grep -E "(code|mysql)" | grep -E "(bash|sh|curl|wget|nc)"
# Audit network listening ports for unauthorized exposuress -tlpn | grep -E "()"5. Mitigation & Defense-in-Depth Remediation Steps
Section titled “5. Mitigation & Defense-in-Depth Remediation Steps”-
Apply Official Oracle Vendor Patches: Upgrade MySQL Shell (Shell for VS Code) to release 2026.2.1+9.6.2 or later immediately following the Oracle Critical Patch Update guidance.
-
Enforce Network Segmentation & Access Control: Restrict access to port
TCP 4300-4350 (Internal Shell RPC) / HTTP. Under no circumstances should management, routing, or internal shell RPC endpoints be exposed to the public Internet or untrusted subnets. -
Audit Privileges and Role Assignments: Review database user grants (
SUPER,REPLICATION SLAVE,BACKUP_ADMIN). Ensure the principle of least privilege is rigorously applied across application and operator service accounts. -
Rotate Infrastructure Credentials: If compromise or unauthorized access is suspected, immediately rotate database administrative passwords, TLS certificates, and Kubernetes service account tokens.