Description
MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB RPM packages created the dedicated mysql service account with the database data directory as its home directory. A database user with the FILE privilege could write startup dot-files such as .bash_profile into $HOME, and those files could execute when an administrator opened a login shell for the mysql account. Debian packages are not affected because they use /nonexistent as the account home. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.
Published: 2026-10-09
Score: 8.4 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation via Unauthorized File Write
Action: Immediate Patch
AI Analysis

Impact

MariaDB RPM packages created the mysql service account with the database data directory as its home directory. A database user who has the FILE privilege can write shell startup files such as .bash_profile into the account’s $HOME directory. When an administrator opens a login shell for the mysql account, these files are executed, allowing the attacker to run arbitrary code with the privileges of the mysql system user. The vulnerability therefore permits an attacker who can create or modify database files to execute code in the context of the mysql service account, potentially compromising database security and confidentiality.

Affected Systems

The issue affects MariaDB Server versions 10.6.1 through 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2 when installed via RPM packages on distributions that allow the mysql account to inherit the database data directory as $HOME. Debian packages are not affected because they assign /nonexistent as the account home. All affected releases are listed in the advisory and the vulnerability is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.4, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is a local attacker who already has a database user with FILE privileges; such a user can write to the mysql system account’s $HOME. Exploitation requires the attacker to control database files and to trigger a login shell for the mysql user, which is common for administrators. Given the high CVSS score and the fact that the flaw allows arbitrary code execution in a privileged account, the risk to impacted deployments is significant.

Generated by OpenCVE AI on October 9, 2026 at 17:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade MariaDB Server to a fixed release (10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, or 13.0.2) following the vendor’s update guidance
  • Limit database users to the minimal set of privileges, ensuring no users are granted the FILE privilege unless absolutely necessary
  • If upgrading is delayed, reconfigure the mysql system account to use a nonexistent or controlled home directory that does not permit execution of startup files

Generated by OpenCVE AI on October 9, 2026 at 17:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Mariadb
Mariadb server
Vendors & Products Mariadb
Mariadb server

Fri, 09 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 09 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
Description MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB RPM packages created the dedicated mysql service account with the database data directory as its home directory. A database user with the FILE privilege could write startup dot-files such as .bash_profile into $HOME, and those files could execute when an administrator opened a login shell for the mysql account. Debian packages are not affected because they use /nonexistent as the account home. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.
Title MariaDB: Insecure $HOME in MariaDB rpm packages
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T16:45:15.295Z

Reserved: 2026-10-08T21:23:59.822Z

Link: CVE-2026-107814

cve-icon Vulnrichment

Updated: 2026-10-09T16:16:13.381Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-09T16:17:26.150

Modified: 2026-10-09T17:16:45.853

Link: CVE-2026-107814

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T17:30:08Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource