CVE-2026-44170 (matched: mariadb)

  • Thursday, 6th August, 2026
  • 04:05am

A security flaw has been identified in MariaDB, a popular open-source database software that many websites use to store critical information like user data, site content, and order records.

This issue only impacts MariaDB installations running on Windows servers that have the CONNECT engine and REST support turned on. Because input from a database table’s HTTP setting is not properly filtered before being added to system commands, a bad actor could potentially run unauthorized commands on the server hosting your database. This could lead to stolen data, site outages, or loss of control over your website and its stored information.

The MariaDB team has already released patches for this vulnerability in updated versions: 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2. Users running MariaDB on other operating systems, or without the CONNECT engine and REST support enabled, are not impacted by this flaw.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-44170

« Back