CVE-2026-107814
Last modified
CVE-2026-107814 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB RPM packages created the dedicated mysql service account with the database data directory as its home directory.
Description
MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB RPM packages created the dedicated mysql service account with the database data directory as its home directory. A database user with the FILE privilege could write startup dot-files such as .bash_profile into $HOME, and those files could execute when an administrator opened a login shell for the mysql account. Debian packages are not affected because they use /nonexistent as the account home. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| MariaDB | server | >= 10.6.1, < 10.6.28; >= 10.11.1, < 10.11.19; >= 11.4.1, < 11.4.13; >= 11.8.1, < 11.8.9; >= 12.3.1, < 12.3.3; >= 13.0.1, < 13.0.2 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-107814?
How severe is CVE-2026-107814?
How do I fix CVE-2026-107814?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-107808Nginx UI is a web user interface for the Nginx web server. F…8.1
- CVE-2026-107809Nginx UI is a web user interface for the Nginx web server. F…8.8
- CVE-2026-107810Nginx UI is a web user interface for the Nginx web server. F…8.1
- CVE-2026-107811Nginx UI is a web user interface for the Nginx web server. F…8.8
- CVE-2026-107812Nginx UI is a web user interface for the Nginx web server. F…7.5
- CVE-2026-107813Nginx UI is a web user interface for the Nginx web server. F…8.8
- CVE-2026-107815MariaDB server is a community developed fork of MySQL server…8.5
- CVE-2026-10782The RealHomes Memberships plugin for WordPress is vulnerable…4.3
- CVE-2026-107828Jivejdon through 5.0 contains an authentication bypass vulne…6.5
- CVE-2026-107829Jivejdon through 5.0 contains a weak password storage vulner…5.9
- CVE-2026-10783A security flaw has been discovered in gradio-app gradio 6.1…2.5
- CVE-2026-107830Jivejdon from commit e0306088 through commit ee67a65e lacks …5.3
Are you affected by CVE-2026-107814?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
