CVE-2026-107822
Last modified
CVE-2026-107822 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB's ACL cache could generate the same database-privilege cache key for role and localhost user names that matched because both used an empty IP component.
Description
MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB's ACL cache could generate the same database-privilege cache key for role and localhost user names that matched because both used an empty IP component. An attacker with CREATE USER could create the colliding principal and, when the original principal's database privileges were cached, exercise privileges assigned to the other account. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| MariaDB | server | >= 10.6.1, < 10.6.28; >= 10.11.1, < 10.11.19; >= 11.4.1, < 11.4.13; >= 11.8.1, < 11.8.9; >= 12.3.1, < 12.3.3; >= 13.0.1, < 13.0.2 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-107822?
How severe is CVE-2026-107822?
How do I fix CVE-2026-107822?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-107817MariaDB server is a community developed fork of MySQL server…4.4
- CVE-2026-107818MariaDB server is a community developed fork of MySQL server…8.4
- CVE-2026-107819MariaDB Connector/C is a C and C++ client library for connec…5.9
- CVE-2026-10782The RealHomes Memberships plugin for WordPress is vulnerable…4.3
- CVE-2026-107820x64dbg-MCP Server is a native Model Context Protocol (MCP) p…5.3
- CVE-2026-107821MariaDB server is a community developed fork of MySQL server…8
- CVE-2026-107823MariaDB server is a community developed fork of MySQL server…7.2
- CVE-2026-107824x64dbg-MCP Server is a native Model Context Protocol (MCP) p…9.3
- CVE-2026-107825OWASP Coraza WAF is a golang modsecurity compatible web appl…4
- CVE-2026-107826OWASP Coraza WAF is a golang modsecurity compatible web appl…7.5
- CVE-2026-107828Jivejdon through 5.0 contains an authentication bypass vulne…6.5
- CVE-2026-107829Jivejdon through 5.0 contains a weak password storage vulner…5.9
Are you affected by CVE-2026-107822?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
