Local File Injection Vulnerability in MariaDB Server by Oracle
CVE-2026-107814

8.4HIGH

Key Information:

Vendor

Mariadb

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107814?

A local file injection vulnerability exists in MariaDB Server where the dedicated mysql service account's home directory is set to the database data directory. This allows database users possessing the FILE privilege to create startup files like .bash_profile within the $HOME directory. If an administrator logs into the mysql account, these files could execute, potentially compromising the system. This issue was not present in Debian packages due to their configuration using /nonexistent as the account home. The vulnerability has been addressed in the following versions: 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.

Affected Version(s)

server >= 10.6.1, < 10.6.28 < 10.6.1, 10.6.28

server >= 10.11.1, < 10.11.19 < 10.11.1, 10.11.19

server >= 11.4.1, < 11.4.13 < 11.4.1, 11.4.13

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.