MariaDB Connector, SQL Injection Vulnerability, CVE-2026-107385 (High) -DC-Oct2026-2955

Listen to this Post

The vulnerability stems from a flaw in how text-protocol string and binary parameter escaping is handled within the MariaDB database connector. When an application passes user-supplied inputs as query parameters using standard text-protocol escaping functions like Connection.escape(), the connector routinely relies on prepending backslashes to escape special characters such as single quotes. However, the internal implementation completely failed to check or consult the session’s active SQL mode configuration—specifically the NO_BACKSLASH_ESCAPES server status flag (STATUS_NO_BACKSLASH_ESCAPES). Under a session or server instance where NO_BACKSLASH_ESCAPES is explicitly enabled, the backslash character loses its special escaping property and is treated strictly as an ordinary literal character. Consequently, quote characters must instead be properly escaped by doubling them rather than backslash-escaping them. Because the connector persisted in prepending backslashes while ignoring the server flag, the generated output prematurely broke out of the intended string literal context. This behavior allowed malicious parameters passed via standard placeholder mechanisms to be interpreted directly as executable SQL commands, thereby introducing a severe SQL injection vulnerability into dependent database applications.

DailyCVE Form:

Platform: MariaDB Connector
Version: All prior versions
Vulnerability : SQL Injection
Severity: High
date: 2026-06-15

Prediction: 2026-06-25

What Undercode Say:

Analytics:

The core flaw involves a mismatch between client-side string sanitization and server-side parsing rules under the NO_BACKSLASH_ESCAPES SQL mode. Because text-protocol entry points omit status flag verification, backslashes are incorrectly inserted instead of doubling quote characters.

Exploit: (Educational Purposes!)

-- Injecting a single quote when NO_BACKSLASH_ESCAPES is active:
-- Parameter input: ' OR '1'='1
-- Flawed output produced by connector: \' OR \'1\'='1
-- Resulting text protocol evaluation breaks the string literal context and executes injected SQL.

Protection:

Upgrade the MariaDB connector package to the patched release version where escaping routines properly branch on session status flags. Alternatively, avoid enabling NO_BACKSLASH_ESCAPES or use parameterized prepared statements via execute() and batch() methods which transmit parameters out-of-band.

Impact:

An attacker capable of influencing query parameters can execute arbitrary SQL statements with the full privileges of the application’s database user, allowing them to read, modify, or delete sensitive data across connected databases.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top