
CyStack@CyStackSecurity
CVE-2026-85985: Authorization bypass in the CONNECT engine of @mariadb Server, the open-source database with 8.3k GitHub stars. UDFs like json_file() and jfile_make() read and write files without checking the FILE privilege or secure_file_priv. A low-privileged SQL account reaches any file the MariaDB process can. Patched in 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, 13.0.2. Found by a CyStack researcher. Details at https://cystack.net/disclosures #CyStack #CyberSecurity #Vulnerability #MariaDB #Database #EnterpriseSecurity #InfoSec
0000048
3.7K followersView on X
