CVE-2026-85985

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-06: 110-06
Referenced assets1 URL
By indicator
Full discourse1 post
  • CyStack@CyStackSecurity

    CVE-2026-85985: Authorization bypass in the CONNECT engine of @mariadb Server, the open-source database with 8.3k GitHub stars. UDFs like json_file() and jfile_make() read and write files without checking the FILE privilege or secure_file_priv. A low-privileged SQL account reaches any file the MariaDB process can. Patched in 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, 13.0.2. Found by a CyStack researcher. Details at https://cystack.net/disclosures #CyStack #CyberSecurity #Vulnerability #MariaDB #Database #EnterpriseSecurity #InfoSec

    0000048
    3.7K followersView on X

Explore more