logo

CVE-2026-40342: CVSS 10.0 Path Traversal to RCE in Firebird Database

ID: b29e7e89-c9cb-5efa-b887-8a8d98288db3

STIX ID: report--b29e7e89-c9cb-5efa-b887-8a8d98288db3

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-22

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical path traversal vulnerability (CVE-2026-40342, CVSS 10.0) in Firebird’s engine/plugin loader lets any user with CREATE FUNCTION privileges craft an engine name that walks out of the plugins directory and causes the server to load a malicious shared library, whose initialization executes immediately with the database process’s OS privileges (commonly firebird/root or SYSTEM); administrators are urged to apply patched versions immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.