CVE-2026-44170 (matched: mariadb)

  • Tuesday, 4th August, 2026
  • 10:04am

A security vulnerability has been found in MariaDB, a popular open-source database tool many websites use to store content, user data, and other site information. This flaw only impacts MariaDB running on Windows servers that have the CONNECT engine installed with REST support enabled.

The issue stems from improper handling of input from HTTP table attributes, which is passed directly to system command lines without being checked for malicious content. If exploited, this could allow an unauthorized person to run unwanted, unapproved commands on the affected server.

The vulnerability affects the following MariaDB version ranges: 10.6.1 up to (but not including) 10.6.26, 10.11.1 up to (but not including) 10.11.17, 11.4.1 up to (but not including) 11.4.11, 11.8.1 up to (but not including) 11.8.7, and version 12.3.1. Patched versions that resolve this issue are 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-44170

« Back