HackerOne Disclosed Reports - 2026-09-07

0 Replies, 5 Views

Logo
High
resolved

MariaDB GRANT PROXY permits unauthorized authentication changes and administrator account takeover


Bug reported by kevin_Mizu was disclosed at September 7, 2026, 8:07 pm   |   Improper Access Control - Generic

A vulnerability was discovered in MariaDB that allowed an authenticated user with only USAGE privileges to change the password of an existing administrator account. This was achieved through the grantee clause of the GRANT PROXY statement, which permitted bypassing the authorization checks and directly modifying the target account's authentication information. The vulnerability was tested on MariaDB versions 12.3.2 and 13.1.0.


Logo
Medium
resolved

MariaDB: heap buffer overflow in ha_tina::chain_append() lets a low-privileged user crash the server via CSV row deletion


Bug reported by Vertical was disclosed at September 7, 2026, 7:59 pm   |   Heap Overflow

A heap buffer overflow vulnerability was discovered in the ha_tina::chain_append() function of the MariaDB database server. The vulnerability was caused by an incorrect memory allocation during the growth of a data structure. This could allow a low-privileged user to crash the server by executing a specific SQL command involving CSV data deletion. The vulnerability was confirmed to affect both the stock Ubuntu package and a source build of MariaDB.


Logo
Medium
resolved

ACL cache collision lets a role inherit privileges from a same-named socket user


Bug reported by was disclosed at September 7, 2026, 7:55 pm   |   Improper Authentication - Generic

A vulnerability was discovered in MariaDB's database privilege cache where a role and a UNIX-socket user with the same name were not distinguished. When the socket user warmed the cache with their privileges, a different account that activated the same-named role then received the cached user privileges, even though those privileges were never granted to the role.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)