Mariadb · Mariadb Connector/C · CVE-2026-61700
**Name of the Vulnerable Software and Affected Versions**
MariaDB Connector/J versions prior to 2.7.14
MariaDB Connector/J versions prior to 3.3.5
MariaDB Connector/J versions prior to 3.4.3
MariaDB Connector/J versions prior to 3.5.9
**Description**
MariaDB Connector/J fails to enforce the `allowLocalInfile=false` setting when processing a server-initiated LOCAL INFILE protocol packet `0xfb` within the `ClientMessage.readPacket()` function. If an application sends a `LOAD DATA LOCAL INFILE` COM QUERY, a rogue or man-in-the-middle server can echo the same filename, tricking the connector into transmitting the file content even if the security option is disabled. Exploitation is limited because the server cannot redirect the request to arbitrary paths and can only receive the specific file already selected by the application. This requires an application to actively load sensitive data over an untrusted connection.
**Recommendations**
Update MariaDB Connector/J to version 2.7.14 or later.
Update MariaDB Connector/J to version 3.3.5 or later.
Update MariaDB Connector/J to version 3.4.3 or later.
Update MariaDB Connector/J to version 3.5.9 or later.