CVE-2023-39593: MariaDB
Medium severity, CVSS 5.6. EPSS: 0.7% chance of exploitation in the next 30 days.
Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.
Affected products
- MariaDB MariaDB: version 10.5.0 only
Published 2024-10-17. Last modified 2026-06-17.