Database Privilege Collision in MariaDB Server
CVE-2026-107822
6.4MEDIUM
What is CVE-2026-107822?
A vulnerability in the MariaDB server affects the Access Control List (ACL) cache, where an attacker with the ability to create users could exploit a collision between role and localhost usernames. This occurs due to both entities using an empty IP component, leading to a mismatched database-privilege cache key. Consequently, an attacker could gain unauthorized access to privileges granted to another account, posing a significant security threat. The issue has been addressed in several versions, enhancing protection against such exploits.
Affected Version(s)
server >= 10.6.1, < 10.6.28 < 10.6.1, 10.6.28
server >= 10.11.1, < 10.11.19 < 10.11.1, 10.11.19
server >= 11.4.1, < 11.4.13 < 11.4.1, 11.4.13
