MariaDB discloses a batch of eight server CVEs (CVSS up to 8.5) plus Connector/C and Connector/Node.js flaws: CONNECT engine stack write, RPM home-directory dot-file and wsrep restart injection by FILE-privileged users, FRM parsing and privilege-escalation bugs; fixed in 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3 and 13.0.2
MariaDB published GitHub security advisories and CVEs on 8–9 October 2026 for issues already fixed in its August releases (for example 11.8.9 on 24 August). Server versions from 10.6.1 before 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3 and 13.0.2 are affected. CVE-2026-107815 (CVSS 3.1 8.5): the CONNECT engine's DOS table type has a bad boundary check allowing a one-byte null write past a stack buffer at an attacker-chosen offset. CVE-2026-107814 (8.4): RPM packages gave the mysql service account the data directory as its home, so a database user with FILE privilege can plant .bash_profile-style files that run when an administrator opens a login shell as mysql. CVE-2026-107818 (8.4): a FILE-privileged user who can write to /run/mysqld can create wsrep-new-cluster and inject environment values into the next service restart. CVE-2026-107821 (8.0): weak validation of binary FRM metadata lets a crafted FRM file in the data directory cause out-of-bounds reads or writes and possibly code execution. CVE-2026-107823 (7.2): newlines in a username can inject view security metadata and escalate privileges. CVE-2026-107816 and CVE-2026-107822 (6.4) cover a qc_info heap over-read and an ACL cache key collision; CVE-2026-107817 (4.4) a mysql_json plugin over-read. Connector/C 3.4.1–3.4.9 does not reject a TLS hostname mismatch before choosing a non-hashing auth plugin (CVE-2026-107819, 5.9; fixed 3.4.10), and Connector/Node.js with permitSetMultiParamEntries lets object keys reach a SQL SET clause unescaped (CVE-2026-107384, 8.1; fixed 3.2.5, 3.3.4, 3.4.7, 3.5.4). No exploitation reported. Primary: MariaDB GitHub security advisories.
- Product
- MariaDB Server; MariaDB Connector/C; MariaDB Connector/Node.js
- Versions
- Server 10.6.1 to before 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, 13.0.2; Connector/C 3.4.1 to before 3.4.10; Connector/Node.js 3.2.0 to before 3.2.5, 3.3.4, 3.4.7, 3.5.4
- CVSS
- 8.5 (CVSS 3.1, CVE-2026-107815); 8.4 (CVE-2026-107814, CVE-2026-107818); 8.1 (Connector/Node.js CVE-2026-107384)
- Exploited in Australia?
- unknown
- Patch to
- Upgrade MariaDB Server to 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3 or 13.0.2 (or later); Connector/C to 3.4.10; Connector/Node.js to 3.2.5, 3.3.4, 3.4.7 or 3.5.4. Limit FILE, CREATE USER and CREATE VIEW WITH GRANT OPTION privileges, set secure_file_priv to a dedicated folder, and disable the CONNECT engine if unused.
Primary: MariaDB server — GitHub security advisories (8–9 Oct 2026) · Vendor: MariaDB Community Server 11.8.9 release (24 Aug 2026) · CVE: CVE-2026-107815, CVE-2026-107814, CVE-2026-107818, CVE-2026-107821, CVE-2026-107823, CVE-2026-107816, CVE-2026-107822, CVE-2026-107817, CVE-2026-107819, CVE-2026-107384 · MariaDB GHSA-m5gf-432r-g5jw — RPM mysql home directory dot-file execution (CVE-2026-107814)
