CVE-2026-55857 | MariaDB Connector/J up to 2.7.13/3.3.4/3.4.2/3.5.8 PAM handler SendPamAuthPacketFactory sslMode/restrictedAuth channel accessible

SecurityVulns

A vulnerability identified as problematic has been detected in MariaDB Connector and J up to 2.7.13/3.3.4/3.4.2/3.5.8. Affected by this vulnerability is the function SendPamAuthPacketFactory of the component PAM handler. This manipulation of the argument sslMode/restrictedAuth causes channel accessible by non-endpoint.

The identification of this vulnerability is CVE-2026-55857. It is possible to initiate the attack remotely. There is no exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More