CVE-2026-44170 (matched: mariadb)

  • Monday, 3rd August, 2026
  • 16:04pm

A security flaw has been identified in MariaDB, a common open-source database software many websites use to store data. This issue only impacts MariaDB installations running on Windows servers that have the CONNECT engine enabled with REST support turned on. The vulnerability occurs because unvetted input from HTTP table settings is passed directly into system command lines without proper filtering. This creates an opening for an attacker to execute unauthorized commands on the affected server if they can access the vulnerable MariaDB instance. The impacted MariaDB versions are 10.6.1 up to (but not including) 10.6.26, 10.11.1 up to (but not including) 10.11.17, 11.4.1 up to (but not including) 11.4.11, 11.8.1 up to (but not including) 11.8.7, and version 12.3.1. Fixes for this issue are already available in updated MariaDB releases: 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-44170

« Back