Local Infile Vulnerability in MariaDB Connector/J Affects Java Applications
CVE-2026-61700

3.7LOW

Key Information:

Vendor
CVE Published:
17 September 2026

What is CVE-2026-61700?

The MariaDB Connector/J vulnerability allows a rogue or man-in-the-middle server to exploit the ClientMessage.readPacket method when processing a server-initiated LOCAL INFILE protocol packet. This issue arises due to the failure to enforce 'allowLocalInfile=false' in applications that send LOAD DATA LOCAL INFILE COM_QUERY. Although the server cannot redirect requests to arbitrary paths, an attacker can echo the filename and force the connector to transmit the file if sensitive data is loaded over an untrusted connection. The problem has been addressed in the following releases: 2.7.14, 3.3.5, 3.4.3, and 3.5.9.

Affected Version(s)

mariadb-connector-j < 2.7.14 < 2.7.14

mariadb-connector-j >= 3.0.0, < 3.3.5 < 3.0.0, 3.3.5

mariadb-connector-j >= 3.4.0, < 3.4.3 < 3.4.0, 3.4.3

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.