CVE-2026-55854
### Summary When PAM (dialog) authentication is used, the connector can be coerced into sending the account password in cleartext over an insecure connection. A hostile or man-in-the-middle server can trigger this with the default configuration, disclosing the user's password. ### Details The mysql_clear_password plugin is gated behind a secure connection: the driver refuses to transmit the password in cleartext over plain TCP. The sibling PAM plugin handler (SendPamAuthPacketFactory, server-side plugin name dialog) did not override that gate and inherited the default value false, so it was not subject to the same secure-transport requirement. As a result, a hostile or man-in-the-middle server can issue an Authentication Switch Request for the dialog plugin over plain TCP, and the driver responds with the user's password in cleartext. With the default configuration (sslMode=DISABLE, restrictedAuth=null) this is reachable with no non-default options. ### Am I affected? You are affected if all of the following hold: You use mariadb Connector/Node.js at a version below the patched release(s). Connections can occur over an insecure transport: plain TCP (sslMode=DISABLE), or a TLS mode that establishes server identity only via self-signed-certificate fingerprint validation. An attacker can occupy an on-path (MITM) position, or otherwise cause the client to connect to a server they control, and present an Authentication Switch Request for the dialog plugin. Connections over properly verified TLS or a local Unix socket are not exposed to this vector. ### Impact Disclosure of the authenticating account's password in cleartext to an on-path or hostile server. The captured credentials can then be reused to authenticate to the database (and, if reused elsewhere, beyond it). ### Patches Fixed in 3.2.4, 3.3.3, 3.4.6, and 3.5.3. Upgrade to the patched release on your branch (3.5.x → 3.5.3, 3.4.x → 3.4.6, 3.3.x → 3.3.3, 3.2.x and earlier → 3.2.4). PAM (dialog) is now t
Properties
- ghsa_id
- GHSA-42r5-vhpq-m858
- severity
- medium
- summary
- MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
- cvss_score
- 5.9
- cve_id
- CVE-2026-55854
- cvss_vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- is_ghsa_only
- false
- ghsa_published
- 2026-08-28T22:04:53Z
- source_url
- https://github.com/advisories/GHSA-42r5-vhpq-m858
- ghsa_updated
- 2026-08-28T22:04:54Z
Related Entities (5)
HAS_WEAKNESS (2)
REPORTED_BY (1)
AFFECTS (1)
VULNERABLE_TO (1)
Explore deeper with Ninja Signal's threat intelligence graph