File Injection Vulnerability in MariaDB Server by Community Vendor
CVE-2026-107818
What is CVE-2026-107818?
The MariaDB server, a community-developed fork of MySQL, contains a vulnerability in the service unit behavior that permits file injection during the service restart process. Specifically, when the mariadb.service unit was configured to use /run/mysqld/wsrep-new-cluster during restarts, a database user possessing FILE privileges and a secure-file-priv setting that allows writes to this directory could create a file to manipulate environment values. This opens a door for potential abuse, allowing an attacker to gain control over the service configuration upon restart. This issue has been mitigated in the latest versions of MariaDB.
Affected Version(s)
server >= 10.6.1, < 10.6.28 < 10.6.1, 10.6.28
server >= 10.11.1, < 10.11.19 < 10.11.1, 10.11.19
server >= 11.4.1, < 11.4.13 < 11.4.1, 11.4.13
