Local Infile Vulnerability in MariaDB Connector/J Affects Java Applications
CVE-2026-61700
What is CVE-2026-61700?
The MariaDB Connector/J vulnerability allows a rogue or man-in-the-middle server to exploit the ClientMessage.readPacket method when processing a server-initiated LOCAL INFILE protocol packet. This issue arises due to the failure to enforce 'allowLocalInfile=false' in applications that send LOAD DATA LOCAL INFILE COM_QUERY. Although the server cannot redirect requests to arbitrary paths, an attacker can echo the filename and force the connector to transmit the file if sensitive data is loaded over an untrusted connection. The problem has been addressed in the following releases: 2.7.14, 3.3.5, 3.4.3, and 3.5.9.
Affected Version(s)
mariadb-connector-j < 2.7.14 < 2.7.14
mariadb-connector-j >= 3.0.0, < 3.3.5 < 3.0.0, 3.3.5
mariadb-connector-j >= 3.4.0, < 3.4.3 < 3.4.0, 3.4.3
