PT-2026-94379 · Mariadb · Mariadb Connector/C

·

CVE-2026-61700

·

Published

2026-09-17

·

Updated

2026-09-23

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions MariaDB Connector/J versions prior to 2.7.14 MariaDB Connector/J versions prior to 3.3.5 MariaDB Connector/J versions prior to 3.4.3 MariaDB Connector/J versions prior to 3.5.9
Description MariaDB Connector/J fails to enforce the allowLocalInfile=false setting when processing a server-initiated LOCAL INFILE protocol packet 0xfb within the ClientMessage.readPacket() function. If an application sends a LOAD DATA LOCAL INFILE COM QUERY, a rogue or man-in-the-middle server can echo the same filename, tricking the connector into transmitting the file content even if the security option is disabled. Exploitation is limited because the server cannot redirect the request to arbitrary paths and can only receive the specific file already selected by the application. This requires an application to actively load sensitive data over an untrusted connection.
Recommendations Update MariaDB Connector/J to version 2.7.14 or later. Update MariaDB Connector/J to version 3.3.5 or later. Update MariaDB Connector/J to version 3.4.3 or later. Update MariaDB Connector/J to version 3.5.9 or later.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61700
ECHO-E63A-AC26-7D97
GHSA-WXMM-Q36W-R9XJ

Affected Products

Mariadb Connector/C