THREAT OPS › Threat News › [GHSA] GHSA-wxmm-q36w-r9xj (low) — MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requests
[GHSA] GHSA-wxmm-q36w-r9xj (low) — MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requests
GHSA-wxmm-q36w-r9xj Severity: low CVE: CVE-2026-61700
MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requests
## Summary
MariaDB Connector/J does not enforce `allowLocalInfile=false` when processing server-initiated LOCAL INFILE requests (protocol packet type `0xfb`). However, exploitation is constrained: the server can only request the exact fi
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-61700cve
Original source: https://github.com/advisories/GHSA-wxmm-q36w-r9xj