Redpacketsecurity MariaDB Vulnerabilities Allow Unauthorized File Access and Privilege Escalation
Article Content
- •CVE-2026-102523 allows unauthorized file access via CONNECT plugin functions.
- •Users can exploit table names as filesystem paths to alter global account data.
- •MariaDB has released fixes for both vulnerabilities; immediate updates are recommended.
Two vulnerabilities in MariaDB's CONNECT plugin and table handling were disclosed on October 7, 2026. The first, tracked as CVE-2026-102523, allows users with basic read access to read and write server-side files without proper privilege checks. The second vulnerability enables users with table-creation privileges to manipulate table names as filesystem paths, potentially altering global account data. Both vulnerabilities were confirmed by MariaDB and are now resolved in subsequent releases. Administrators are advised to apply security updates and review account changes if their systems may have been exposed. The issues highlight significant flaws in permission enforcement and path validation within MariaDB's architecture.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-102523 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What are the specific CVEs for these vulnerabilities?
How can I protect my MariaDB installation?
Is there evidence of active exploitation?
Continue Reading
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…