CVE-2026-55854 | MariaDB Connector/Node.js up to 3.2.3/3.3.2/3.4.5/3.5.2 PAM Authentication pam-password-auth.js SendPamAuthPacketFactory missing encryption
A vulnerability was found in MariaDB Connector and Node.js up to 3.2.3/3.3.2/3.4.5/3.5.2 and classified as problematic. This vulnerability affects the function SendPamAuthPacketFactory of the file lib/cmd/handshake/auth/pam-password-auth.js of the component PAM Authentication. The manipulation results in missing encryption of sensitive data.
This vulnerability is known as CVE-2026-55854. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More