CVE-2023-26785: MariaDB
Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.
MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.
Affected products
- MariaDB MariaDB: version 10.5.0 only
Published 2024-10-17. Last modified 2026-06-17.