THREAT OPS › Threat News › [GHSA] GHSA-42r5-vhpq-m858 (medium) — MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
[GHSA] GHSA-42r5-vhpq-m858 (medium) — MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
GHSA-42r5-vhpq-m858 Severity: medium CVE: CVE-2026-55854
MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
### Summary
When PAM (dialog) authentication is used, the connector can be coerced into sending the account password in cleartext over an insecure connection. A hostile or man-in-the-middle server can trigger this with the default configur
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-55854cve
Original source: https://github.com/advisories/GHSA-42r5-vhpq-m858