Redpacketsecurity
HackerOne Bug Bounty Disclosures: Critical Vulnerabilities in KILL and MariaDB
Article Content
On September 7, 2026, two significant vulnerabilities were reported through HackerOne. The first involves the KILL authorization mechanism, which improperly trusts the presented login name instead of the authenticated anonymous account, potentially allowing unauthorized access. The second vulnerability affects MariaDB's GRANT PROXY feature, permitting unauthorized changes to authentication and risking administrator account takeover. Both vulnerabilities were submitted by different researchers and have implications for systems utilizing these technologies. The KILL vulnerability was submitted by user 'dogeshark', while the MariaDB issue was reported by 'kevin_Mizu'. The reports highlight the need for immediate attention and remediation to prevent exploitation.
Key Points: • KILL authorization vulnerability allows unauthorized access via improper trust in login names. • MariaDB GRANT PROXY flaw enables unauthorized authentication changes and potential account takeover. • Both vulnerabilities were submitted on September 7, 2026, and require urgent remediation.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.