CVE-2023-39593: MariaDB

Medium severity, CVSS 5.6. EPSS: 0.7% chance of exploitation in the next 30 days.

Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

Affected products

  • MariaDB MariaDB: version 10.5.0 only

Published 2024-10-17. Last modified 2026-06-17.