CVE-2026-107823
Received Received - Intake

MariaDB View Parser Privilege Escalation via Newline Injection

Vulnerability report for CVE-2026-107823, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the MariaDB view FRM parser did not safely encode embedded newline characters in a username. An account with CREATE USER and CREATE VIEW WITH GRANT OPTION could create a crafted username containing additional view metadata, causing the parser to interpret part of the username as security metadata and potentially escalating database privileges. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
MariaDB server >= 10.6.1, < 10.6.28
MariaDB server >= 10.11.1, < 10.11.19
MariaDB server >= 11.4.1, < 11.4.13
MariaDB server >= 11.8.1, < 11.8.9
MariaDB server >= 12.3.1, < 12.3.3
MariaDB server >= 13.0.1, < 13.0.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-144 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as line delimiters when they are sent to a downstream component.
CWE-116 The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in MariaDB involves improper parsing of view .frm files when a username contains a newline character. An attacker with CREATE USER and CREATE VIEW WITH GRANT OPTION privileges can craft a username with embedded newlines and metadata, causing the parser to misinterpret security metadata and potentially escalate database privileges.

Detection Guidance

Check MariaDB server version using 'mysql --version' or 'SELECT VERSION();'. If running affected versions (10.6.1-10.6.27, 10.11.1-10.11.18, 11.4.1-11.4.12, 11.8.1-11.8.8, 12.3.1-12.3.2, 13.0.1), the system is vulnerable. Review user accounts with CREATE USER and CREATE VIEW WITH GRANT OPTION privileges for usernames containing special characters.

Impact Analysis

If exploited, this vulnerability could allow an attacker to escalate their database privileges, gaining unauthorized access to sensitive data or performing actions beyond their intended permissions. The attack requires high privileges but no user interaction and impacts confidentiality, integrity, and availability.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements for GDPR, HIPAA, and other regulations that mandate strict access controls and data protection. Exploitation may result in data breaches, triggering legal and financial penalties.

Mitigation Strategies

Upgrade MariaDB to patched versions (10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, 13.0.2) immediately. If upgrading is not possible, revoke CREATE VIEW WITH GRANT OPTION privileges from untrusted users and recreate existing views with definers that include special characters.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107823. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart