Skip to content
Remote Code Execution Vulnerabilities Disclosed in MariaDB

Remote Code Execution Vulnerabilities Disclosed in MariaDB

First seen 8 Oct 2026, 20:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 20:34 UTC
  • •Two RCE vulnerabilities reported in MariaDB could be exploited by low-privilege users.
  • •The vulnerabilities involve use-after-free and heap over-read conditions.
  • •No patches or confirmed exploitation have been reported yet.

Two separate reports submitted to HackerOne detail vulnerabilities in MariaDB that could lead to remote code execution (RCE). The first report, submitted by Rick de Jager, describes a low-privilege RCE vulnerability involving an use-after-free condition in SYS_REFCURSOR and a heap over-read related to ST_Area. The second report, by Akhil Koul, highlights a heap use-after-free vulnerability in Materialized_cursor::open due to SYS_REFCURSOR array reallocation. Both vulnerabilities rely on memory safety issues and could potentially allow attackers with low-level privileges to execute arbitrary code on the database server. The reports lack detailed technical information, including proof of concept and affected versions. As of now, there is no confirmation of exploitation in the wild, and the vulnerabilities remain.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-07
Vulnerability reports submitted to HackerOne
Rick de Jager and Akhil Koul submitted reports detailing RCE vulnerabilities in MariaDB.
Redpacketsecurity
2026-10-07
Second vulnerability report submitted
Akhil Koul submitted a report on a heap use-after-free vulnerability in Materialized_cursor::open.
Redpacketsecurity

More articles in this cluster (2)

Common questions

What are the main vulnerabilities reported?
The reports detail a low-privilege RCE vulnerability and a heap use-after-free vulnerability in MariaDB.
Is there any patch available for these vulnerabilities?
No patches have been reported for these vulnerabilities as of now.
Are these vulnerabilities being actively exploited?
There is currently no confirmation of exploitation in the wild.