MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.07642}

epss

{'score': 0.13877}


Sun, 20 Oct 2024 23:45:00 +0000

Type Values Removed Values Added
Description MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability. MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.
References

Sat, 19 Oct 2024 01:30:00 +0000

Type Values Removed Values Added
Title mariadb: RCE vulnerability
Weaknesses CWE-754
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 18 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Mariadb
Mariadb mariadb
Weaknesses CWE-94
CPEs cpe:2.3:a:mariadb:mariadb:10.5.0:*:*:*:*:*:*:*
Vendors & Products Mariadb
Mariadb mariadb
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Oct 2024 21:45:00 +0000

Type Values Removed Values Added
Description MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-10-20T23:39:53.553411

Reserved: 2023-02-27T00:00:00

Link: CVE-2023-26785

cve-icon Vulnrichment

Updated: 2024-10-18T19:03:14.630Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-17T22:15:02.743

Modified: 2025-07-10T19:06:29.667

Link: CVE-2023-26785

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-10-17T00:00:00Z

Links: CVE-2023-26785 - Bugzilla

cve-icon OpenCVE Enrichment

No data.