A security issue has been identified for MariaDB, a popular open-source database software used by many websites to store content, user information, and other site data. The flaw only impacts MariaDB installations running on Windows servers that have the CONNECT engine enabled and REST support turned on.
The problem occurs when the software processes certain HTTP-related table settings without proper validation, which could allow an unauthorized user to run commands directly on the server hosting the database. This could potentially let someone access, modify, or delete your website's stored data, or disrupt your site's normal functionality.
Affected MariaDB versions include 10.6.1 up to (but not including) 10.6.26, 10.11.1 up to before 10.11.17, 11.4.1 up to before 11.4.11, 11.8.1 up to before 11.8.7, and version 12.3.1. The issue has already been fixed in updated releases: 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-44170