Local File Injection Vulnerability in MariaDB Server by Oracle
CVE-2026-107814
What is CVE-2026-107814?
A local file injection vulnerability exists in MariaDB Server where the dedicated mysql service account's home directory is set to the database data directory. This allows database users possessing the FILE privilege to create startup files like .bash_profile within the $HOME directory. If an administrator logs into the mysql account, these files could execute, potentially compromising the system. This issue was not present in Debian packages due to their configuration using /nonexistent as the account home. The vulnerability has been addressed in the following versions: 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.
Affected Version(s)
server >= 10.6.1, < 10.6.28 < 10.6.1, 10.6.28
server >= 10.11.1, < 10.11.19 < 10.11.1, 10.11.19
server >= 11.4.1, < 11.4.13 < 11.4.1, 11.4.13
