PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107818 MariaDB CVE debrief

CVE-2026-107818 is a high-severity vulnerability in MariaDB server that allows environment injection via wsrep bootstrap in the mariadb.service file. A database user with FILE privilege and a secure-file-priv configuration permitting writes to /run/mysqld could create a file and inject attacker-controlled environment values into the restarted service.

Vendor
MariaDB
Product
server
CVSS
HIGH 8.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-09
Original CVE updated
2026-10-09
Advisory published
2026-10-09
Advisory updated
2026-10-09

Who should care

Defenders responsible for MariaDB server deployments, specifically those using versions 10.6.1 through 10.6.28, 10.11.1 through 10.11.19, 11.4.1 through 11.4.13, 11.8.1 through 11.8.9, 12.3.1 through 12.3.3, and 13.0.1 through 13.0.2, should prioritize patching and restricting FILE privilege to necessary users.

Why it matters

CVE-2026-107818 is a high-severity vulnerability in MariaDB server that allows environment injection via wsrep bootstrap in the mariadb.service file. Defenders should prioritize patching vulnerable versions and restricting FILE privilege to necessary users.

  • Potential environment injection and privilege escalation
  • Possible service disruption or compromise
  • Requires verification of vulnerable versions and configurations
  • Patching and configuration changes are necessary to mitigate the vulnerability

Technical summary

The mariadb.service unit uses /run/mysqld/wsrep-new-cluster during the next service restart. A database user with FILE privilege and a secure-file-priv configuration permitting writes to /run/mysqld could create that file and inject attacker-controlled environment values into the restarted service. This issue affects MariaDB server versions 10.6.1 through 10.6.28, 10.11.1 through 10.11.19, 11.4.1 through 11.4.13, 11.8.1 through 11.8.9, 12.3.1 through 12.3.3, and 13.0.1 through 13.0.2. Defenders should prioritize patching vulnerable versions and restricting FILE privilege to necessary users.

Defensive priority

Defenders should prioritize patching vulnerable versions of MariaDB server, specifically versions 10.6.1 through 10.6.28, 10.11.1 through 10.11.19, 11.4.1 through 11.4.13, 11.8.1 through 11.8.9, 12.3.1 through 12.3.3, and 13.0.1 through 13.0.2.

Recommended defensive actions

  • Patch vulnerable versions of MariaDB server
  • Restrict FILE privilege to necessary users
  • Configure secure-file-priv to limit write access
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The vulnerability is caused by the mariadb.service unit using /run/mysqld/wsrep-new-cluster during the next service restart. A database user with FILE privilege and a secure-file-priv configuration permitting writes to /run/mysqld could create that file and inject attacker-controlled environment values into the restarted service.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107818 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107818

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107818 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107818

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • MariaDB: environment injection via wsrep bootstrap in the mariadb.service file

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107818.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MariaDB/server/security/advisories/GHSA-mhvc-vqcq-7vq5

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MariaDB/server/commit/e3d62d4e78fd4941cef3f5053e6a50d0b32d740e

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MariaDB/server/releases/tag/mariadb-10.11.19

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MariaDB/server/releases/tag/mariadb-10.6.28

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MariaDB/server/releases/tag/mariadb-11.4.13

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MariaDB/server/releases/tag/mariadb-11.8.9

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MariaDB/server/releases/tag/mariadb-12.3.3

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.