Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107822— MariaDB: database privilege escalation via user / role name collision in the acl cache

Quick assessment

Affected
MariaDB server
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MariaDB 服务器是 MySQL 服务器的一个社区开发分支。在版本 10.6.1 到 10.6.28、10.11.19、11.4.13、11.8.9、12.3.3 以及 13.0.2 之间,MariaDB 的访问控制列表(ACL)缓存可能会为角色(role)和本地主机(localhost)用户名生成相同的数据库权限缓存键,原因是两者都使用了空的 IP 组件。攻击者若拥有 CREATE USER 权限,便可创建产生碰撞的主账户;当原始主账户的数据库权限被缓存后,攻击者即可利用该缓存行使分配给另一账户的权限。此问题

CVSS 6.4 · Medium

Affected Version Matrix 6

VendorProduct Version RangeStatus
MariaDB server >= 10.6.1, < 10.6.28 affected
>= 10.11.1, < 10.11.19 affected
>= 11.4.1, < 11.4.13 affected
>= 11.8.1, < 11.8.9 affected
>= 12.3.1, < 12.3.3 affected
>= 13.0.1, < 13.0.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107822

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MariaDB: database privilege escalation via user / role name collision in the acl cache
Source: CVE Program / CVE List V5
Vulnerability Description
MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB's ACL cache could generate the same database-privilege cache key for role and localhost user names that matched because both used an empty IP component. An attacker with CREATE USER could create the colliding principal and, when the original principal's database privileges were cached, exercise privileges assigned to the other account. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用不正确的解析名称或索引
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MariaDB server >= 10.6.1, < 10.6.28 -

II. Public POCs for CVE-2026-107822

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107822

请登录查看更多情报信息。

Other References for CVE-2026-107822 (9)

Same Patch Batch · MariaDB · 2026-10-09 · 9 CVEs total

CVE-2026-107815 8.5 HIGH MariaDB: one byte OOB write in DOS tables of the CONNECT engine
CVE-2026-107814 8.4 HIGH MariaDB: Insecure $HOME in MariaDB rpm packages
CVE-2026-107818 8.4 HIGH MariaDB: environment injection via wsrep bootstrap in the mariadb.service file
CVE-2026-107821 8.0 HIGH MariaDB: insufficient validation of binary frm data when opening a table
CVE-2026-107823 7.2 HIGH MariaDB: privilege escalation via incorrect view frm parsing
CVE-2026-107816 6.4 MEDIUM MariaDB: `qc_info` plugin can do OOB reads if query contains \0
CVE-2026-107819 5.9 MEDIUM MariaDB Connector/C: libmariadb allowed cleartext password leakage on TLS hostname verific
CVE-2026-107817 4.4 MEDIUM MariaDB: mysql_json plugin OOB reads

IV. Related Vulnerabilities

V. Comments for CVE-2026-107822

No comments yet


Leave a comment