Firebird disclosed two high-severity vulnerabilities affecting versions prior to 5.0.4, 4.0.7, and 3.0.14, including a path traversal and arbitrary file write issue tracked as CVE-2026-40342. The flaw resides in the external engine plugin loader, which improperly concatenates a user-controlled engine name into a filesystem path without filtering path separators or .. sequences. An authenticated user with CREATE FUNCTION privileges can abuse the bug to load an arbitrary shared library from disk, causing its initialization code to run immediately under the Firebird server's operating system account and resulting in remote code execution.
A second vulnerability, CVE-2026-28224, allows an unauthenticated attacker to crash a Firebird server by sending an op_crypt_key_callback packet before authentication, triggering a null pointer dereference because the port_server_crypt_callback handler is not initialized. The denial-of-service condition requires only network access to the server's IP address and port. Firebird addressed both issues in releases 5.0.4, 4.0.7, and 3.0.14, with advisories indicating the bugs carry high impact across availability and, in the case of CVE-2026-40342, confidentiality and integrity as well.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-40342 was disclosed as a Firebird vulnerability in which improper path handling in the external engine plugin loader lets an authenticated user with CREATE FUNCTION privileges load an arbitrary shared library. Successful exploitation can execute code as the Firebird server operating system account.
GitHub Security Advisories received and published CVE-2026-28224 on April 17, 2026, documenting a network-accessible null pointer dereference in Firebird's CryptCallback handling. The flaw allows an unauthenticated attacker to crash vulnerable Firebird servers.
Firebird released versions 5.0.4, 4.0.7, and 3.0.14 to address two security flaws: a path traversal and arbitrary file write issue leading to remote code execution, and a null pointer dereference in CryptCallback that can cause denial of service. The fixes apply to all affected versions prior to those releases.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.