CVE-2026-107822

Source
https://cve.org/CVERecord?id=CVE-2026-107822
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107822.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107822
Aliases
  • GHSA-2m85-2x26-36rf
Downstream
Published
2026-10-09T17:28:47Z
Modified
2026-10-10T07:09:22Z
Severity
  • 6.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
MariaDB: database privilege escalation via user / role name collision in the acl cache
Details

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB's ACL cache could generate the same database-privilege cache key for role and localhost user names that matched because both used an empty IP component. An attacker with CREATE USER could create the colliding principal and, when the original principal's database privileges were cached, exercise privileges assigned to the other account. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-706",
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107822.json"
}
References

Affected packages

Git / github.com/mariadb/server

Affected ranges

Type
GIT
Repo
https://github.com/mariadb/server
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "10.6.1"
        },
        {
            "fixed": "10.6.28"
        },
        {
            "introduced": "10.11.1"
        },
        {
            "fixed": "10.11.19"
        },
        {
            "introduced": "11.4.1"
        },
        {
            "fixed": "11.4.13"
        },
        {
            "introduced": "11.8.1"
        },
        {
            "fixed": "11.8.9"
        },
        {
            "introduced": "12.3.1"
        },
        {
            "fixed": "12.3.3"
        },
        {
            "introduced": "13.0.1"
        },
        {
            "fixed": "13.0.2"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

mariadb-10.*
mariadb-10.6.1
mariadb-10.6.10
mariadb-10.6.11
mariadb-10.6.12
mariadb-10.6.13
mariadb-10.6.14
mariadb-10.6.16
mariadb-10.6.17
mariadb-10.6.18
mariadb-10.6.19
mariadb-10.6.2
mariadb-10.6.20
mariadb-10.6.21
mariadb-10.6.22
mariadb-10.6.23
mariadb-10.6.24
mariadb-10.6.25
mariadb-10.6.26
mariadb-10.6.27
mariadb-10.6.3
mariadb-10.6.4
mariadb-10.6.5
mariadb-10.6.6
mariadb-10.6.8
mariadb-10.6.9
mariadb-11.*
mariadb-11.4.1
mariadb-11.4.10
mariadb-11.4.11
mariadb-11.4.11b
mariadb-11.4.2
mariadb-11.4.3
mariadb-11.4.4
mariadb-11.4.5
mariadb-11.4.6
mariadb-11.4.7
mariadb-11.4.8
mariadb-11.4.9
mariadb-11.8.1
mariadb-11.8.2
mariadb-11.8.3
mariadb-11.8.4
mariadb-11.8.6
mariadb-11.8.7
mariadb-11.8.7b
mariadb-12.*
mariadb-12.3.1
mariadb-13.*
mariadb-13.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107822.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "339712868486696881928202886484344029960",
            "length": 1715
        },
        "id": "CVE-2026-107822-1cd3e8db",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/mariadb/server/commit/83e909fc2a0dbc394b4b683fb3fa2d7dcf26cc5e",
        "target": {
            "file": "sql/log_event_server.cc",
            "function": "Rows_log_event_fragmenter::fragment"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "265577632303887446289749120585557906012",
                "90338461107598051749602183626527029076",
                "135974257990159682542061181314070611477",
                "59440921527566409168742990730026725636",
                "871135494022066138858656571240698570",
                "247293449498909397416026347351022219912",
                "179396894775406735805665784479451940140",
                "269443033021460921618747189093528286356",
                "259691733175197008076763079871985256069",
                "102338916828131457031608538914692707050",
                "65381815336936246662830619643818353906",
                "7100122396357284882133944108516856108",
                "161393146120866756988306743699529625075"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107822-6d62851c",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/mariadb/server/commit/bf9193a939f515e95dd8def1a5468088c91cede6",
        "target": {
            "file": "sql/item_vectorfunc.cc"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "19396654230727680862231874232577326830",
            "length": 1414
        },
        "id": "CVE-2026-107822-96fb114a",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/mariadb/server/commit/210ab6edf47fa73f3b77e974ed2e9357ccdd051c",
        "target": {
            "file": "sql/sql_acl.cc",
            "function": "sp_revoke_privileges"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "73617688475456381632237133958511949829",
            "length": 361
        },
        "id": "CVE-2026-107822-c0933a1f",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/mariadb/server/commit/bf9193a939f515e95dd8def1a5468088c91cede6",
        "target": {
            "file": "sql/item_vectorfunc.cc",
            "function": "Item_func_vec_fromtext::fix_length_and_dec"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "171922335289695664967320282302097012127",
                "314879264303882873216162120692739820747",
                "296657960952465744719770094395708912555",
                "28908880241426286725700820784852115102"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107822-e432b228",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/mariadb/server/commit/83e909fc2a0dbc394b4b683fb3fa2d7dcf26cc5e",
        "target": {
            "file": "sql/log_event_server.cc"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "183641122820527899892205997373469390336",
                "12095135203163139841028791777804307677",
                "261887274333923489567884393156281229573",
                "19596961056601881646204718953590518429",
                "25158190267319178375799434564910426458",
                "79868031186840623159971036872671971261",
                "200778640584501115234958299261030732588",
                "131021480572983927965383857652169015703",
                "259210579588990591926922975771411684670",
                "308293174102341777206582901688760031968",
                "89478837310948837990084826679872794784",
                "338867660209294619394468737325384824268",
                "65149555481557669088217935797404683315",
                "105820217938288583399134742620391383975",
                "267805393157920367530703819131918882708",
                "38039493077906535068223160253483389044",
                "155248208230518966475406644089911097304",
                "209055380163172280650138201893193615240",
                "272836316798595100180885698601052815062",
                "139632117011298755459574139848637089730",
                "112587756624072824044503235660869015796",
                "209449771227581042596611529590064743564",
                "56162312170597687179668831370098686864",
                "315300952757613979287910862404135586893",
                "124631588903503696531604192284802908081",
                "198447588607325890124688444202645428954",
                "277625244959498228703902376649148264741",
                "330117756961362545716991630961872097576",
                "261593920518145687707482140334066129492",
                "310029719624151742354329969579957852433",
                "127355466400457567574110878344968834572",
                "234782324348854453769025645027188821308",
                "4933798797732149183640097703596172566",
                "78315220821823291688255278082772905562",
                "283495978258419445643401192492072153310",
                "289680889044596507883491876189615178669",
                "77013134991366103256989980017263461542"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107822-ebba965d",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/mariadb/server/commit/210ab6edf47fa73f3b77e974ed2e9357ccdd051c",
        "target": {
            "file": "sql/sql_acl.cc"
        }
    }
]
vanir_signatures_modified
"2026-10-10T07:09:22Z"