CVE-2023-26785: MariaDB

Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.

MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

Affected products

  • MariaDB MariaDB: version 10.5.0 only

Published 2024-10-17. Last modified 2026-06-17.