CVE-2026-32710Disclosure(mariadb / mariadb)

HIGHCVSS 9.9 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch mariadb mariadb systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possible to turn the crash into a remote code execution. These conditions require tight control over memory layout which is generally only attainable in a lab environment. This issue is fixed in MariaDB 11.4.10, MariaDB 11.8.6, and MariaDB 12.2.2.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mariadb

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 13 mentions across 11 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 11 signals
  • Disclosure: 7 classified signals
  • Peaked 10d ago at 2 mentions (2026-03-20); latest day: 1
  • 13 total mentions across 11 days

Affected systems

Vendors
Products
mariadb

1 version affected across 1 product

Deep dive

Activity timeline13 mentions / 11d
01122Mentions · 2026-03-20: 2Mentions · 2026-03-22: 1Mentions · 2026-03-24: 1Mentions · 2026-03-25: 2Mentions · 2026-03-27: 1Mentions · 2026-03-28: 1Mentions · 2026-03-29: 1Mentions · 2026-05-06: 1Mentions · 2026-05-07: 1Mentions · 2026-05-08: 1Mentions · 2026-05-12: 1PoC Mentioned / Linked · 2026-05-06: 1PoC Mentioned / Linked · 2026-05-08: 1Exploit Tool / Code · 2026-05-06: 1Exploit Tool / Code · 2026-05-08: 1Active Exploitation · 2026-03-25: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-24: 1Patch / Workaround · 2026-03-25: 2Patch / Workaround · 2026-03-29: 1Technical Details · 2026-03-20: 2Technical Details · 2026-03-22: 1Technical Details · 2026-03-24: 1Technical Details · 2026-03-25: 2Technical Details · 2026-03-28: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-12: 103-2003-2203-2403-2503-2703-2803-2905-0605-0705-0805-12
Signal classification3 categories
Disclosure
753.8%
Patch
430.8%
PoC
215.4%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-202
Disclosure2
2026-03-221
Disclosure1
2026-03-241
Patch1
2026-03-252
Patch2
2026-03-271
Disclosure1
2026-03-281
Disclosure1
2026-03-291
Patch1
2026-05-061
PoC1
2026-05-071
Disclosure1
2026-05-081
PoC1
2026-05-121
Disclosure1
Full discourse13 posts
  • Nicolas Krassas@Dinosn
    PoC

    CVE-2026-32710, Heap OOB write in MariaDB JSON_SCHEMA_VALID() → persistent privilege escalation (lab-assisted, created with raptor) https://github.com/dinosn/CVE-2026-32710

    Post summary

    The post shares a GitHub repository containing a proof‑of‑concept for CVE-2026-32710, a heap OOB write in MariaDB’s JSON_SCHEMA_VALID() that enables persistent privilege escalation.

    16031132.1K
    158.1K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    PostgreSQL の脆弱性 CVE-2026-2005/2006 が FIX:Wiz の http://ZeroDay.Cloud イベント https://iototsecnews.jp/2026/05/04/wiz-zeroday-cloud-event-reveals-20-year-old-postgresql-vulnerabilities/ 世界中で広く利用されているデータベース PostgreSQL に、20 年近くも前から潜んでいた深刻な脆弱性が発見されました。問題の原因は、データベース内で暗号化や復号を行うためのエクステンション pgcrypto に存在する、データの長さを正しく確認しない不備にあります。具体的には、悪意を持って細工されたメッセージや文字データを処理しようとすると、あらかじめ用意されたメモリの範囲を超えてデータが書き込まれてしまうオーバーフローが発生します (CVE-2026-2005/CVE-2026-2006)。これにより、データベース権限の乗っ取りや、サーバ上での任意のコマンド実行に至る恐れがあります。また、 MariaDB でも、メモリ管理の不具合の脆弱性 (CVE-2026-32710) が見つかっています。ご利用のチームは、ご注意ください。 #CVE20262005 #CVE20262006 #CVE202632710 #PostgreSQL #Vulnerability #ZeroDayCloud

    Post summary

    The post announces the discovery of the long‑hidden PostgreSQL vulnerabilities CVE‑2026‑2005/2006, outlines the buffer‑overflow flaw in pgcrypto and the potential for RCE, but provides no exploits, patches, or evidence of active exploitation.

    02010138
    491 followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 تهديد استقرار قواعد بيانات MariaDB بسبب ثغرة خطيرة في JSON Schema أصدرت MariaDB تحديثات لمعالجة ثغرة (buffer overflow) عالية الخطورة، CVE-2026-32710. يستغل المهاجمون هذه الثغرات لتعطيل الخدمات أو تنفيذ تعليمات برمجية عن بعد. يُنصح بتطبيق التحديثات الأمنية الصادرة فورًا للتخفيف من المخاطر وحماية الأنظمة. 🔗 للمزيد: https://securityonline.info/mariadb-json-schema-validation-buffer-overflow-vulnerability-cve-2026-32710/

    Post summary

    The text announces a patch for MariaDB’s JSON Schema buffer overflow vulnerability (CVE‑2026‑32710), urging users to apply the update immediately to prevent exploitation.

    00030340
    81 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    MariaDB patches a high-severity buffer overflow (CVE-2026-32710) in its JSON validation function. Upgrade to 11.4.10 or 11.8.6 to prevent server crashes. #MariaDB #CyberSecurity #DatabaseSecurity #PatchAlert #InfoSec #Vulnerability #JSON #OpenSource #CVE https://securityonline.info/mariadb-json-schema-validation-buffer-overflow-vulnerability-cve-2026-32710/ https://t.co/aijQpEVxPo

    Post summary

    The tweet announces MariaDB’s patch for CVE-2026-32710, a high‑severity buffer overflow in JSON validation, and urges users to upgrade to versions 11.4.10 or 11.8.6 to mitigate the risk.

    00021262
    10.9K followersView on X
  • Dr.Mashari@GMashari
    Patch

    📌 تهديد استقرار قواعد بيانات MariaDB بسبب ثغرة خطيرة في JSON Schema 🛡️ الفئة: ثغرة 📝 الملخص: أصدرت MariaDB تحديثات حاسمة لمعالجة ثغرة تجاوز سعة المخزن المؤقت (buffer overflow) عالية الخطورة، مُتعقبة بالرمز CVE-2026-32710. تؤثر هذه الثغرة، المرتبطة بالتحقق من صحة مخطط JSON (JSON Schema validation)، بشكل مباشر على استقرار قواعد بيانات MariaDB مفتوحة المصدر. يستغل المهاجمون هذه الثغرات لتعطيل الخدمات أو تنفيذ تعليمات برمجية عن بعد. يُنصح بتطبيق التحديثات الأمنية الصادرة فورًا للتخفيف من المخاطر وحماية الأنظمة. 🗓️ تاريخ النشر: 24/03/2026 🔗 للمزيد: https://securityonline.info/mariadb-json-schema-validation-buffer-overflow-vulnerability-cve-2026-32710/

    Post summary

    MariaDB released critical updates to address CVE‑2026‑32710, a buffer overflow in JSON Schema validation, while noting that attackers are actively exploiting the flaw.

    0101078
    9.0K followersView on X
  • ✪ 𝕱𝖆𝖍𝖆𝖉@fad_777
    PoC

    اكتشاف CVE-2026-32710: ثغرة في MariaDB تؤدي إلى تصعيد الامتيازات بشكل دائم. تم التحقق منها باستخدام أدوات متقدمة. CVE-2026-32710 exposes a vulnerability in MariaDB, leading to persistent privilege escalation. Verified through advanced tools. https://github.com/dinosn/CVE-2026-32710 #CyberSecurity #MariaDB #Vulnerability

    Post summary

    The post announces the discovery of CVE-2026-32710 in MariaDB, indicates persistent privilege escalation, and provides a GitHub link that likely contains a proof‑of‑concept, but does not mention active exploitation or patching.

    0000035
    63 followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    Heap OOB write through a JSON schema validation function leading to persistent privesc - the attack surface hiding in database built-ins is consistently underestimated. CVE-2026-32710 is tracked on http://vulntracker.io. If MariaDB is anywhere in your stack, this one's worth a close look.

    Post summary

    The post reveals a newly tracked MariaDB vulnerability (CVE-2026-32710) involving a heap out‑of‑bounds write via JSON schema validation that can lead to persistent privilege escalation, but offers no PoC, exploit code, or patch information.

    0000081
    619 followersView on X
  • IntegSec@integ_sec
    Patch

    CVE-2026-32710: MariaDB Server Crash Flaw - What It Means for Your Business and How to Respond https://hubs.li/Q048LP7D0

    Post summary

    The article outlines the impact of the MariaDB Server Crash Flaw and offers remedial steps, likely emphasizing the need to apply vendor patches.

    0000020
    31 followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Disclosure

    MariaDBに深刻度「高」のバッファオーバーフロー 脆弱性(CVE-2026-32710) https://rocket-boys.co.jp/security-measures-lab/mariadb-high-severity-buffer-overflow-vulnerability-cve-2026-32710/

    Post summary

    The text announces a high‑severity buffer overflow vulnerability (CVE‑2026‑32710) in MariaDB.

    0000051
    39 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    MariaDBに深刻度「高」のバッファオーバーフロー 脆弱性(CVE-2026-32710) https://rocket-boys.co.jp/security-measures-lab/mariadb-high-severity-buffer-overflow-vulnerability-cve-2026-32710/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The post announces a high‑severity buffer overflow in MariaDB identified as CVE-2026-32710, but does not provide additional details, PoC, exploit code, or mitigation information.

    00000110
    364 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32710 MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in… https://www.cve.org/CVERecord?id=CVE-2026-32710

    Post summary

    The text discloses a crash vulnerability in MariaDB for authenticated users on specific versions, without providing PoC details or mitigation.

    0000080
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-32710 - High MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() func... https://www.thehackerwire.com/vulnerability/CVE-2026-32710/ https://t.co/VxwdAODURC

    Post summary

    The post announces a high‑severity crash vulnerability in MariaDB, detailing affected versions and the faulty JSON_SCHEMA_VALID() function, but lacks any PoC, exploit, or patch information.

    0000037
    138 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-32710: HIGH] Vulnerability alert: Authenticated users can crash MariaDB server before versions 11.4.10 & 11.8.6 via bug in JSON_SCHEMA_VALID() function, possible remote code execution. Fix availabl...#cve,CVE-2026-32710,#cybersecurity https://cvefind.com/CVE-2026-32710

    Post summary

    The post announces a high‑impact vulnerability (CVE‑2026‑32710) affecting MariaDB’s JSON_SCHEMA_VALID() function, allowing authenticated users to crash the server and potentially execute code, and notes that a patch is available.

    0000047
    604 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmariadbmariadb---
Appmariadbmariadb12.1.2--

Explore more