CVE-2026-44170 (matched: mariadb)

  • Wednesday, 5th August, 2026
  • 16:06pm

A security vulnerability identified as CVE-2026-44170 has been discovered in MariaDB, a popular open-source database system used by many websites to store data like user information, site content, and transaction records. This issue only impacts MariaDB installations running on Windows servers that have the CONNECT engine and REST support turned on. The flaw fails to properly sanitize certain input before it is passed to system commands, which could allow an attacker to run unauthorized commands on the server hosting the database. This could lead to data loss, site downtime, or unauthorized access to sensitive information for websites using this affected configuration. The MariaDB team has released official patches for all vulnerable versions. Updating MariaDB to one of the patched releases (10.6.26, 10.11.17, 11.4.11, 11.8.7, or 12.3.2) will resolve this vulnerability for impacted setups.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-44170

« Back