CVE-2026-44170 (matched: mariadb)

  • Monday, 3rd August, 2026
  • 22:04pm

A security vulnerability, tracked as CVE-2026-44170, has been found in MariaDB, a common open-source database tool many websites use to store content, user accounts, and other site information. This issue only affects MariaDB running on Windows servers that have the CONNECT engine installed and have REST support turned on. If your MariaDB setup does not meet these specific criteria, you are not impacted by this flaw.

The flaw occurs because the software fails to properly sanitize a setting tied to table HTTP attributes before passing it to a system command. This creates an opening for an unauthorized user to run commands on your server if they can access the affected REST feature.

If successfully exploited, this could let an attacker access, modify, or delete your website's data, or disrupt your site's normal operation. The MariaDB development team has released fixed versions to resolve this issue: 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2 all include the necessary patch.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-44170

« Back