CVE-2026-44170 (matched: mariadb)

  • Tuesday, 4th August, 2026
  • 22:05pm

A security issue has been identified for MariaDB, a common open-source database tool used to power many dynamic websites. This flaw only impacts specific MariaDB versions running on Windows servers, and only if the server has the CONNECT engine installed and REST support enabled. The vulnerability allows unchecked input from a database table’s HTTP setting to be passed directly into system commands without proper filtering. This could let an unauthorized person run their own commands on the affected server, which may lead to stolen website data, disrupted site functionality, or other harmful activity. Fixes for this issue are already included in updated releases of all impacted MariaDB versions.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-44170

« Back