CVE-2026-44170 (matched: mariadb)

  • Tuesday, 4th August, 2026
  • 16:04pm

A security flaw has been identified in specific versions of MariaDB, a widely used open-source database tool that many websites rely on to store content, user information, and other data. The issue only impacts MariaDB installations running on Windows servers that have the CONNECT engine and REST support feature enabled. The flaw occurs when untrusted input from web requests is passed directly to system commands without proper filtering. This could allow an attacker to run unauthorized commands on the affected server, which may lead to data theft, website defacement, or unauthorized access to sensitive resources. The MariaDB development team has released fixed versions that resolve this issue: 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2. If your hosting environment runs an affected MariaDB version on Windows with those features enabled, updating to one of these patched versions will address the risk.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-44170

« Back