EIP-2026-102932
PRE-CVEMySQL User-Defined (Linux) x32 / x86_64 - 'sys_exec' Local Privilege Escalation (2)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102932. PoCs published by ninpwn.
AI-analyzed exploit summary This exploit leverages MySQL's User-Defined Function (UDF) feature to achieve local privilege escalation on Linux systems by injecting shellcode via a malicious UDF library. It is based on prior exploits (e.g., raptor_udf.c) and targets MySQL 4.x/5.x.
Description
MySQL User-Defined (Linux) x32 / x86_64 - 'sys_exec' Local Privilege Escalation (2)
Exploits (1)
exploitdb
WORKING POC
by ninpwn · pythonlocallinux
https://www.exploit-db.com/exploits/50236
This exploit leverages MySQL's User-Defined Function (UDF) feature to achieve local privilege escalation on Linux systems by injecting shellcode via a malicious UDF library. It is based on prior exploits (e.g., raptor_udf.c) and targets MySQL 4.x/5.x.
Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target:
MySQL 4.x/5.x
Auth required
Prerequisites:
Local access to MySQL server · Ability to create UDFs (requires MySQL credentials)
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026