MariaDB Connector/J: Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
Summary
| CVE | CVE-2026-55857 |
|---|---|
| State | PUBLISHED |
| Assigner | GitHub_M |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-28 23:17:08 UTC |
| Updated | 2026-08-28 23:17:08 UTC |
| Description | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, PAM dialog authentication can be coerced into transmitting the account password over an insecure connection. The mysql_clear_password plugin is gated behind a secure transport, but the sibling PAM handler SendPamAuthPacketFactory, named dialog by the server, does not declare that requirement and inherits the default secure-required value false; older branches implement the same affected behavior in SendPamAuthPacket. A hostile or man-in-the-middle server can send an Authentication Switch Request for dialog over plain TCP, causing the driver to return the user's password in cleartext when sslMode=DISABLE and restrictedAuth=null, which is the default configuration. Properly verified TLS and local Unix sockets are not exposed to this transport vector. This issue is fixed in versions 2.7.14, 3.3.5, 3.4.3, and 3.5.9. |
Risk And Classification
Primary CVSS: v3.1 5.9 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Problem Types: CWE-319 | CWE-522 | CWE-319 CWE-319: Cleartext Transmission of Sensitive Information | CWE-522 CWE-522: Insufficiently Protected Credentials
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.9 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | CNA | DECLARED | 5.9 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Mariadb-corporation | Mariadb-connector-j | affected < 2.7.14 | Not specified |
| CNA | Mariadb-corporation | Mariadb-connector-j | affected >= 3.0.0, < 3.3.5 | Not specified |
| CNA | Mariadb-corporation | Mariadb-connector-j | affected >= 3.4.0, < 3.4.3 | Not specified |
| CNA | Mariadb-corporation | Mariadb-connector-j | affected >= 3.5.0, < 3.5.9 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/mariadb-corporation/mariadb-connector-j/releases/tag/3.4.3 | [email protected] | github.com | |
| github.com/mariadb-corporation/mariadb-connector-j/commit/f4a727c764d1cf... | [email protected] | github.com | |
| github.com/mariadb-corporation/mariadb-connector-j/commit/a8599ab1cbe4b8... | [email protected] | github.com | |
| github.com/mariadb-corporation/mariadb-connector-j/releases/tag/3.5.9 | [email protected] | github.com | |
| jira.mariadb.org/browse/CONJ-1320 | [email protected] | jira.mariadb.org | |
| github.com/mariadb-corporation/mariadb-connector-j/security/advisories/G... | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.