CVE-2026-107814
Awaiting Analysis Awaiting Analysis - Queue

Privilege Escalation via Malicious Startup Files in MariaDB RPM Packages

Vulnerability report for CVE-2026-107814, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB RPM packages created the dedicated mysql service account with the database data directory as its home directory. A database user with the FILE privilege could write startup dot-files such as .bash_profile into $HOME, and those files could execute when an administrator opened a login shell for the mysql account. Debian packages are not affected because they use /nonexistent as the account home. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
MariaDB server >= 10.6.1, < 10.6.28
MariaDB server >= 10.11.1, < 10.11.19
MariaDB server >= 11.4.1, < 11.4.13
MariaDB server >= 11.8.1, < 11.8.9
MariaDB server >= 12.3.1, < 12.3.3
MariaDB server >= 13.0.1, < 13.0.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-732 The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MariaDB server versions between 10.6.1 and 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2 had a flaw where RPM packages created the mysql service account with the database data directory as its home directory. A user with FILE privilege could write malicious dot-files like .bash_profile into this home directory. When an administrator logged into the mysql account, these files could execute arbitrary commands.

Detection Guidance

Check MariaDB version with 'mariadb --version' or 'mysql --version'. If using affected versions (10.6.1-10.6.27, 10.11.1-10.11.18, 11.4.1-11.4.12, 11.8.1-11.8.8, 12.3.1-12.3.2, 13.0.1), the system may be vulnerable. Inspect the mysql service account home directory for unauthorized .bash_profile or similar files.

Impact Analysis

This vulnerability allows an attacker with FILE privilege to gain elevated privileges by executing commands as the mysql service account. This could lead to unauthorized access, data manipulation, or further compromise of the system. Administrators logging into the mysql account could unknowingly trigger malicious scripts.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR's integrity and confidentiality principles or HIPAA's safeguards for protected health information. Organizations may face compliance penalties, legal consequences, and reputational damage if exploited.

Mitigation Strategies

Upgrade MariaDB to a patched version (10.6.28+, 10.11.19+, 11.4.13+, 11.8.9+, 12.3.3+, 13.0.2+). For RPM-based systems, verify the mysql account home directory is not set to the data directory. Remove any unauthorized .bash_profile or similar files in the mysql account home.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107814. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart