HackerOne Bug Bounty Disclosures: Critical Vulnerabilities in KILL and MariaDB

HackerOne Bug Bounty Disclosures: Critical Vulnerabilities in KILL and MariaDB

First seen 8 Sep 2026, 19:20 UTC Redpacketsecurity 51.1

Article Content

Browse articles
ThreatCluster

On September 7, 2026, two significant vulnerabilities were reported through HackerOne. The first involves the KILL authorization mechanism, which improperly trusts the presented login name instead of the authenticated anonymous account, potentially allowing unauthorized access. The second vulnerability affects MariaDB's GRANT PROXY feature, permitting unauthorized changes to authentication and risking administrator account takeover. Both vulnerabilities were submitted by different researchers and have implications for systems utilizing these technologies. The KILL vulnerability was submitted by user 'dogeshark', while the MariaDB issue was reported by 'kevin_Mizu'. The reports highlight the need for immediate attention and remediation to prevent exploitation.

Key Points: • KILL authorization vulnerability allows unauthorized access via improper trust in login names. • MariaDB GRANT PROXY flaw enables unauthorized authentication changes and potential account takeover. • Both vulnerabilities were submitted on September 7, 2026, and require urgent remediation.

Ask AI about this cluster

Timeline

2026-09-07
KILL authorization vulnerability reported
The KILL authorization mechanism was found to trust presented login names, risking unauthorized access.
Redpacketsecurity
2026-09-07
MariaDB GRANT PROXY vulnerability reported
The GRANT PROXY feature in MariaDB was found to allow unauthorized authentication changes, risking admin account takeover.
Redpacketsecurity