THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-wxmm-q36w-r9xj (low) — MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requests

[GHSA] GHSA-wxmm-q36w-r9xj (low) — MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requests

medgithub_advisoriesPublished 2026-09-17

GHSA-wxmm-q36w-r9xj Severity: low CVE: CVE-2026-61700

MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requests

## Summary

MariaDB Connector/J does not enforce `allowLocalInfile=false` when processing server-initiated LOCAL INFILE requests (protocol packet type `0xfb`). However, exploitation is constrained: the server can only request the exact fi

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-wxmm-q36w-r9xj