CVE-2026-15392 is a filesystem boundary enforcement flaw in DBD::File for Perl DBI affecting versions before 1.651. The vulnerable logic is in the complete_table_name method, which constructs the absolute path to a table file but does not verify whether the resolved table file is a symbolic link to an untrusted location. As a result, a symbolic link placed within the configured data directory can reference a file outside the intended f_dir and f_dir_search directories, defeating the directory restriction model used by file-based drivers.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability in DBD::File where a table could be a symlink outside of the configured f_dir boundary.
A vulnerability in DBD::File where a table symlink could point outside the configured f_dir boundary.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.