Exploitation Summary
EIP tracks 1 public exploit for CVE-2026-32710. PoCs published by dinosn.
Description
MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possible to turn the crash into a remote code execution. These conditions require tight control over memory layout which is generally only attainable in a lab environment. This issue is fixed in MariaDB 11.4.10, MariaDB 11.8.6, and MariaDB 12.2.2.
Exploits (1)
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/MariaDB/server/security/advisories/GHSA-4rj5-2227-9wgc
X_Refsource_Misc x_refsource_misc
https://jira.mariadb.org/browse/MDEV-38356
Scores
CVSS v3
8.5
EPSS
0.0086
EPSS Percentile
53.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Lab Environment
Details
CWE
CWE-122
Status
published
Products (5)
mariadb/mariadb
12.1.2
mariadb/mariadb
11.4.1 - 11.4.10
MariaDB/server
>= 11.4.1, < 11.4.10
MariaDB/server
>= 11.8.1, < 11.8.6
MariaDB/server
>= 12.1.2, < 12.2.2
Published
Mar 20, 2026
Tracked Since
Mar 21, 2026