PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107821 MariaDB CVE debrief

The CVE-2026-107821 vulnerability in MariaDB server allows an attacker to trigger out-of-bounds reads or writes, crash the server, or potentially execute code by placing a crafted FRM file in the data directory. This issue affects MariaDB versions from 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2. The vulnerability is caused by insufficient validation of binary frm data when opening a table, which can lead to out-of-bounds reads or writes, crashes, or potential code execution. Defenders responsible for MariaDB server instances, particularly those using affected versions, should assess exposure and prioritize patching to prevent potential crashes or code.

Vendor
MariaDB
Product
server
CVSS
HIGH 8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-09
Original CVE updated
2026-10-09
Advisory published
2026-10-09
Advisory updated
2026-10-09

Who should care

Defenders responsible for MariaDB server instances, particularly those using affected versions, should assess exposure and prioritize patching to prevent potential crashes or code execution.

Why it matters

CVE-2026-107821 is a high-severity vulnerability in MariaDB server that requires prompt attention from defenders to prevent potential crashes or code execution. Affected versions must be patched or updated to prevent exposure.

  • Potential crashes or code execution require immediate attention to prevent service disruption or security breaches.
  • Verification of inventory and patching of vulnerable instances is crucial to prevent exposure.
  • Monitoring for unusual activity or crashes is necessary to detect potential exploitation attempts.

Technical summary

The MariaDB server vulnerability CVE-2026-107821 is caused by insufficient validation of binary frm data when opening a table. This can lead to out-of-bounds reads or writes, crashes, or potential code execution. The vulnerability affects MariaDB versions from 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2. Defenders should prioritize patching vulnerable MariaDB server instances to prevent potential crashes or code execution. The vulnerability is a high-severity issue that requires prompt attention from defenders to prevent potential crashes or code execution.

Defensive priority

Defenders should prioritize patching vulnerable MariaDB server instances to prevent potential crashes or code execution.

Recommended defensive actions

  • Patch vulnerable MariaDB server instances to versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, or 13.0.2.
  • Verify inventory of MariaDB server instances to identify potential exposure.
  • Monitor for unusual activity or crashes in MariaDB server instances.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and source item provide details on the vulnerability, affected versions, and fixed versions. However, there is no information on known exploitation or victims. The vulnerability is a high-severity issue that requires prompt attention from defenders to prevent potential crashes or code execution. Affected versions must be patched or updated to prevent exposure. The CVE Program record and NVD detail page provide official information on the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107821 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107821

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107821 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107821

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • MariaDB: insufficient validation of binary frm data when opening a table

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107821.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MariaDB/server/security/advisories/GHSA-c4gx-34mg-95q5

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MariaDB/server/commit/3b1c2e58abab5571bec4ff52773ddc75b1738da9

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MariaDB/server/releases/tag/mariadb-10.11.19

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MariaDB/server/releases/tag/mariadb-10.6.28

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MariaDB/server/releases/tag/mariadb-11.4.13

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MariaDB/server/releases/tag/mariadb-11.8.9

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MariaDB/server/releases/tag/mariadb-12.3.3

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.