PT-2026-107252 · Undefined · Undefined
CVE-2026-85985
·
Publicado
2026-10-06
·
Atualizado
2026-10-06
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
CVE-2026-85985: Authorization bypass in the CONNECT engine of @mariadb Server, the open-source database with 8.3k GitHub stars.
UDFs like json file() and jfile make() read and write files without checking the FILE privilege or secure file priv. A low-privileged SQL account reaches any file the MariaDB process can.
Patched in 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, 13.0.2. Found by a CyStack researcher. Details at https://t.co/jttYqwzWqR
#CyStack #CyberSecurity #Vulnerability #MariaDB #Database #EnterpriseSecurity #InfoSec
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Undefined