PT-2026-107252 · Undefined · Undefined
CVE-2026-85985
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
CVE-2026-85985: Authorization bypass in the CONNECT engine of @mariadb Server, the open-source database with 8.3k GitHub stars.
UDFs like json file() and jfile make() read and write files without checking the FILE privilege or secure file priv. A low-privileged SQL account reaches any file the MariaDB process can.
Patched in 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, 13.0.2. Found by a CyStack researcher. Details at https://t.co/jttYqwzWqR
#CyStack #CyberSecurity #Vulnerability #MariaDB #Database #EnterpriseSecurity #InfoSec
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined