PatchSiren cyber security CVE debrief
CVE-2026-107821 MariaDB CVE debrief
The CVE-2026-107821 vulnerability in MariaDB server allows an attacker to trigger out-of-bounds reads or writes, crash the server, or potentially execute code by placing a crafted FRM file in the data directory. This issue affects MariaDB versions from 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2. The vulnerability is caused by insufficient validation of binary frm data when opening a table, which can lead to out-of-bounds reads or writes, crashes, or potential code execution. Defenders responsible for MariaDB server instances, particularly those using affected versions, should assess exposure and prioritize patching to prevent potential crashes or code.
- Vendor
- MariaDB
- Product
- server
- CVSS
- HIGH 8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-09
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-09
- Advisory updated
- 2026-10-09
Who should care
Defenders responsible for MariaDB server instances, particularly those using affected versions, should assess exposure and prioritize patching to prevent potential crashes or code execution.
Why it matters
CVE-2026-107821 is a high-severity vulnerability in MariaDB server that requires prompt attention from defenders to prevent potential crashes or code execution. Affected versions must be patched or updated to prevent exposure.
- Potential crashes or code execution require immediate attention to prevent service disruption or security breaches.
- Verification of inventory and patching of vulnerable instances is crucial to prevent exposure.
- Monitoring for unusual activity or crashes is necessary to detect potential exploitation attempts.
Technical summary
The MariaDB server vulnerability CVE-2026-107821 is caused by insufficient validation of binary frm data when opening a table. This can lead to out-of-bounds reads or writes, crashes, or potential code execution. The vulnerability affects MariaDB versions from 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2. Defenders should prioritize patching vulnerable MariaDB server instances to prevent potential crashes or code execution. The vulnerability is a high-severity issue that requires prompt attention from defenders to prevent potential crashes or code execution.
Defensive priority
Defenders should prioritize patching vulnerable MariaDB server instances to prevent potential crashes or code execution.
Recommended defensive actions
- Patch vulnerable MariaDB server instances to versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, or 13.0.2.
- Verify inventory of MariaDB server instances to identify potential exposure.
- Monitor for unusual activity or crashes in MariaDB server instances.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and source item provide details on the vulnerability, affected versions, and fixed versions. However, there is no information on known exploitation or victims. The vulnerability is a high-severity issue that requires prompt attention from defenders to prevent potential crashes or code execution. Affected versions must be patched or updated to prevent exposure. The CVE Program record and NVD detail page provide official information on the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107821 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107821
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107821 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107821
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
MariaDB: insufficient validation of binary frm data when opening a table
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107821.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/MariaDB/server/security/advisories/GHSA-c4gx-34mg-95q5
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/MariaDB/server/commit/3b1c2e58abab5571bec4ff52773ddc75b1738da9
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/MariaDB/server/releases/tag/mariadb-10.11.19
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/MariaDB/server/releases/tag/mariadb-10.6.28
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/MariaDB/server/releases/tag/mariadb-11.4.13
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/MariaDB/server/releases/tag/mariadb-11.8.9
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/MariaDB/server/releases/tag/mariadb-12.3.3
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.