PatchSiren cyber security CVE debrief
CVE-2026-107818 MariaDB CVE debrief
CVE-2026-107818 is a high-severity vulnerability in MariaDB server that allows environment injection via wsrep bootstrap in the mariadb.service file. A database user with FILE privilege and a secure-file-priv configuration permitting writes to /run/mysqld could create a file and inject attacker-controlled environment values into the restarted service.
- Vendor
- MariaDB
- Product
- server
- CVSS
- HIGH 8.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-09
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-09
- Advisory updated
- 2026-10-09
Who should care
Defenders responsible for MariaDB server deployments, specifically those using versions 10.6.1 through 10.6.28, 10.11.1 through 10.11.19, 11.4.1 through 11.4.13, 11.8.1 through 11.8.9, 12.3.1 through 12.3.3, and 13.0.1 through 13.0.2, should prioritize patching and restricting FILE privilege to necessary users.
Why it matters
CVE-2026-107818 is a high-severity vulnerability in MariaDB server that allows environment injection via wsrep bootstrap in the mariadb.service file. Defenders should prioritize patching vulnerable versions and restricting FILE privilege to necessary users.
- Potential environment injection and privilege escalation
- Possible service disruption or compromise
- Requires verification of vulnerable versions and configurations
- Patching and configuration changes are necessary to mitigate the vulnerability
Technical summary
The mariadb.service unit uses /run/mysqld/wsrep-new-cluster during the next service restart. A database user with FILE privilege and a secure-file-priv configuration permitting writes to /run/mysqld could create that file and inject attacker-controlled environment values into the restarted service. This issue affects MariaDB server versions 10.6.1 through 10.6.28, 10.11.1 through 10.11.19, 11.4.1 through 11.4.13, 11.8.1 through 11.8.9, 12.3.1 through 12.3.3, and 13.0.1 through 13.0.2. Defenders should prioritize patching vulnerable versions and restricting FILE privilege to necessary users.
Defensive priority
Defenders should prioritize patching vulnerable versions of MariaDB server, specifically versions 10.6.1 through 10.6.28, 10.11.1 through 10.11.19, 11.4.1 through 11.4.13, 11.8.1 through 11.8.9, 12.3.1 through 12.3.3, and 13.0.1 through 13.0.2.
Recommended defensive actions
- Patch vulnerable versions of MariaDB server
- Restrict FILE privilege to necessary users
- Configure secure-file-priv to limit write access
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The vulnerability is caused by the mariadb.service unit using /run/mysqld/wsrep-new-cluster during the next service restart. A database user with FILE privilege and a secure-file-priv configuration permitting writes to /run/mysqld could create that file and inject attacker-controlled environment values into the restarted service.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107818 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107818
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107818 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107818
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
MariaDB: environment injection via wsrep bootstrap in the mariadb.service file
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107818.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/MariaDB/server/security/advisories/GHSA-mhvc-vqcq-7vq5
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/MariaDB/server/commit/e3d62d4e78fd4941cef3f5053e6a50d0b32d740e
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/MariaDB/server/releases/tag/mariadb-10.11.19
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/MariaDB/server/releases/tag/mariadb-10.6.28
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/MariaDB/server/releases/tag/mariadb-11.4.13
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/MariaDB/server/releases/tag/mariadb-11.8.9
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/MariaDB/server/releases/tag/mariadb-12.3.3
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.