CVE-2026-40342: CVSS 10.0 Path Traversal to RCE in Firebird Database
ID: b29e7e89-c9cb-5efa-b887-8a8d98288db3
STIX ID: report--b29e7e89-c9cb-5efa-b887-8a8d98288db3
Feed Name: securityonline.info
Threat Score
A critical path traversal vulnerability (CVE-2026-40342, CVSS 10.0) in Firebird’s engine/plugin loader lets any user with CREATE FUNCTION privileges craft an engine name that walks out of the plugins directory and causes the server to load a malicious shared library, whose initialization executes immediately with the database process’s OS privileges (commonly firebird/root or SYSTEM); administrators are urged to apply patched versions immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
