Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.0

CVE-2025-13699: rootio-mariadb-10.5: Unauthorized access to database possible through root account

CVE-2025-13699 · published 11 days ago
Summary

A bug was found in the rootio-mariadb-10.5 package that could allow an attacker with a root account to access sensitive data in the database without permission. This could potentially lead to unauthorized access to your database. You should update the rootio-mariadb-10.5 package to the latest version to fix this issue.

What to do
  • Update rootio-mariadb-10.5 to version 1:10.5.29-0+deb11u1.root.io.1.
  • Update rootio-mariadb to version 1:10.11.14-0+deb12u2.root.io.3.
  • Update rootio-mariadb to version 1:11.8.3-0+deb13u1.root.io.1.
  • Update debian mariadb to version 1:10.11.18-0+deb12u1.
  • Update debian mariadb to version 11.8.6-0+deb13u1.
  • Update debian mariadb to version 1:11.8.5-1.
  • Update mariadb-10.5 to version 1:10.5.29-0+deb11u1.aikido.2.
  • Update rootio-mariadb-10.5 to version 1:10.5.29-0+deb11u1.aikido.2.
Affected software
Ecosystem VendorProductAffected versions
Root:Debian:11 rootio-mariadb-10.5 < 1:10.5.29-0+deb11u1.root.io.1
< 1:10.5.29-0+deb11u1.aikido.2
Fix: upgrade to 1:10.5.29-0+deb11u1.root.io.1
Root:Debian:12 rootio-mariadb < 1:10.11.14-0+deb12u2.root.io.3
Fix: upgrade to 1:10.11.14-0+deb12u2.root.io.3
Root:Debian:13 rootio-mariadb < 1:11.8.3-0+deb13u1.root.io.1
Fix: upgrade to 1:11.8.3-0+deb13u1.root.io.1
Debian:12 debian mariadb < 1:10.11.18-0+deb12u1
Fix: upgrade to 1:10.11.18-0+deb12u1
Debian:13 debian mariadb < 11.8.6-0+deb13u1
Fix: upgrade to 11.8.6-0+deb13u1
Debian:14 debian mariadb < 1:11.8.5-1
Fix: upgrade to 1:11.8.5-1
Debian:11 debian mariadb-10.5 All versions
Root:Debian:11 mariadb-10.5 < 1:10.5.29-0+deb11u1.aikido.2
Fix: upgrade to 1:10.5.29-0+deb11u1.aikido.2
Original advisory text
CVE-2025-13699 in mariadb-10.5 - Patched by Root
Root has patched CVE-2025-13699 in the mariadb-10.5 package for Root:Debian:11. Multiple fixed versions available.
Severity
7.0 High
CVSS 3.0: 7.0 (NVD)
CVSS 3.1: 7.0 (OSV)
Exploitation
EPSS <1%
Type
CWE-22Path Traversal
Timeline
Published23 Aug 2026
Updated3 Sep 2026
First seen6 Mar 2026
Monitor software like this
Free during beta