Database Privilege Collision in MariaDB Server
CVE-2026-107822

6.4MEDIUM

Key Information:

Vendor

Mariadb

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107822?

A vulnerability in the MariaDB server affects the Access Control List (ACL) cache, where an attacker with the ability to create users could exploit a collision between role and localhost usernames. This occurs due to both entities using an empty IP component, leading to a mismatched database-privilege cache key. Consequently, an attacker could gain unauthorized access to privileges granted to another account, posing a significant security threat. The issue has been addressed in several versions, enhancing protection against such exploits.

Affected Version(s)

server >= 10.6.1, < 10.6.28 < 10.6.1, 10.6.28

server >= 10.11.1, < 10.11.19 < 10.11.1, 10.11.19

server >= 11.4.1, < 11.4.13 < 11.4.1, 11.4.13

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.