CVE-2026-40342Disclosure(firebirdsql / firebird)

MEDIUMCVSS 9.9 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch firebirdsql firebird systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without filtering path separators or .. components. An authenticated user with CREATE FUNCTION privileges can use a crafted ENGINE name to load an arbitrary shared library from anywhere on the filesystem via path traversal. The library's initialization code executes immediately during loading, before Firebird validates the module, achieving code execution as the server's OS account. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-73CWE-94CWE-427

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firebird

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-04-19); latest day: 1
  • 7 total mentions across 6 days

Affected systems

Products
firebird

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1Mentions · 2026-04-19: 2Mentions · 2026-04-21: 1Mentions · 2026-04-22: 1Mentions · 2026-04-23: 1Active Exploitation · 2026-04-23: 1Patch / Workaround · 2026-04-19: 1Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-04-23: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-18: 1Technical Details · 2026-04-19: 2Technical Details · 2026-04-21: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-23: 104-1704-1804-1904-2104-2204-23
Signal classification4 categories
Disclosure
457.1%
General
114.3%
Patch
114.3%
Active Exploitation
114.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-171
Disclosure1
2026-04-181
Disclosure1
2026-04-192
Disclosure1General1
2026-04-211
Patch1
2026-04-221
Disclosure1
2026-04-231
Active Exploitation1
Full discourse7 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - Firebird RCE (CVE-2026-40342) Crafted ENGINE names exploit path traversal in the external engine loader to load arbitrary shared libraries, executing code as the server's OS account. 👉Affected: < v5.0.4, < v4.0.7, < v3.0.14 | Upgrade to v5.0.4, v4.0.7, or v3.0.14 https://t.co/zZ4d8TTTUI

    Post summary

    A newly disclosed Firebird RCE (CVE-2026-40342) allows attackers to use crafted ENGINE names for path traversal, load arbitrary libraries, and execute code as the server's OS account; affected versions are below v5.0.4, v4.0.7, and v3.0.14 and should be upgraded.

    00050134
    238 followersView on X
  • yousukezan@yousukezan
    Disclosure

    Firebirdデータベースにパストラバーサル脆弱性が判明し、最小権限ユーザーからでも最高権限で任意コード実行が可能となる深刻なリスクが明らかになった。 CVE-2026-40342はエンジン/プラグイン読み込み機構に存在するパストラバーサルに起因する。CREATE FUNCTION文のENGINE指定時、入力されたエンジン名がそのままパスに連結されるため、攻撃者は「..」などを用いて任意のディレクトリへ移動し、悪意ある共有ライブラリを読み込ませることができる。FirebirdはdlopenやLoadLibraryExでライブラリを読み込む際、検証前に初期化コードを実行するため、SQL自体が失敗しても攻撃コードは既に実行される。 この脆弱性はCREATE FUNCTION権限を持つユーザーであれば悪用可能で、Linuxではfirebirdユーザーやroot、WindowsではSYSTEM権限で実行される可能性がある。結果として機密データの窃取や横展開、永続化が容易となる。影響バージョンでは制御機構が存在せず、速やかなアップデートが不可欠である。 https://securityonline.info/firebird-database-rce-cve-2026-40342-path-traversal/

    Post summary

    CVE‑2026‑40342 reveals a path traversal flaw in Firebird’s engine/plugin loader that can lead to remote code execution and privilege escalation via CREATE FUNCTION; rapid patching is urgently recommended.

    010111.5K
    13.2K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    ```json { "x": "🚨 CRITICAL: CVE-2026-40342 (CVSS 9.9) - Firebird RDBMS path traversal enables authenticated RCE. Versions <5.0.4, <4.0.7, <3.0.14 affected. Patch immediately. https://t.co/0B9VfBmNHp

    Post summary

    Critical CVE‑2026‑40342 in Firebird RDBMS permits authenticated remote code execution via path traversal; patch immediately.

    0001058
    26 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    Firebird Database CVE-2026-40342 is under active exploitation — attackers can execute remote code via path traversal. CVSS 10.0 severity. Patch now to prevent compromise. #NerdieNews #CyberSecurity #InfoSec #Vulnerability #CloudSecurity #AWS #Apple https://t.co/75HoIRUfu7

    Post summary

    Firebird Database CVE‑2026‑40342 is currently being exploited in the wild to achieve remote code execution via path traversal; an immediate patch is required to mitigate the vulnerability.

    0000049
    55 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40342 Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-… https://www.cve.org/CVERecord?id=CVE-2026-40342

    Post summary

    The post notes the existence of CVE‑2026‑40342 in Firebird, mentioning a technical detail of the vulnerability but providing no proof of exploitation, PoC, or patch.

    0000080
    57.2K followersView on X
  • CTIWatch@ctiwatchcloud
    Disclosure

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-40342 | CVSS 9.9 🔴 CVE-2026-40351 | CVSS 9.8 🔴 CVE-2026-37749 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post lists three high‑CVSS CVEs (CVE‑2026‑40342, CVE‑2026‑40351, CVE‑2026‑37749) as today’s top vulnerabilities, but offers no details on exploitation or mitigations.

    0000081
    5.6K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40342: Firebird: Path Traversal + Arbit... Path traversal in ENGINE parameter bypasses all validation - library init code runs before module checks, making this a... https://zerodaysignal.com/vulnerability/CVE-2026-40342 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-40342, a path traversal vulnerability in Firebird that bypasses validation during library initialization, but it does not provide PoC, exploit code, or patch information.

    0000069
    218 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfirebirdsqlfirebird---

Explore more