---
id: CVE-2026-107822
title: MariaDB server is a community developed fork of MySQL server
summary: >-
  MariaDB server is a community developed fork of MySQL server. From 10.6.1
  until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB's ACL
  cache could generate the same database-privilege cache key for role and
  localhost user …
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-706
  - CWE-863
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T18:17:04.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107822'
references:
  - url: >-
      https://github.com/MariaDB/server/commit/67ea07dd3400004e4f7ae01bf977f4344bbe064b
    label: security-advisories@github.com
  - url: 'https://github.com/MariaDB/server/releases/tag/mariadb-10.11.19'
    label: security-advisories@github.com
  - url: 'https://github.com/MariaDB/server/releases/tag/mariadb-10.6.28'
    label: security-advisories@github.com
  - url: 'https://github.com/MariaDB/server/releases/tag/mariadb-11.4.13'
    label: security-advisories@github.com
  - url: 'https://github.com/MariaDB/server/releases/tag/mariadb-11.8.9'
    label: security-advisories@github.com
  - url: 'https://github.com/MariaDB/server/releases/tag/mariadb-12.3.3'
    label: security-advisories@github.com
  - url: 'https://github.com/MariaDB/server/releases/tag/mariadb-13.0.2'
    label: security-advisories@github.com
  - url: 'https://github.com/MariaDB/server/security/advisories/GHSA-2m85-2x26-36rf'
    label: security-advisories@github.com
  - url: 'https://jira.mariadb.org/browse/MDEV-40541'
    label: security-advisories@github.com
tags:
  - nvd
ingestedAt: '2026-10-09T19:09:33.753Z'
---

## Overview

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB's ACL cache could generate the same database-privilege cache key for role and localhost user names that matched because both used an empty IP component. An attacker with CREATE USER could create the colliding principal and, when the original principal's database privileges were cached, exercise privileges assigned to the other account. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
