Path traversal in MariaDB - CVE-2026-44171
Published: May 19, 2026
MariaDB
Detailed vulnerability description
The vulnerability allows a local privileged user to create files outside of the target directory.
The vulnerability exists due to path traversal in mbstream when unpacking a specially crafted archive. A local privileged user can supply a crafted archive containing /../ path elements to create files outside of the target directory.
User interaction is required to unpack the crafted archive.