← Back

CVE-2026-3494

nvd nist
Published: Mar 3, 2026Modified: Mar 16, 2026

JSON object

Loading...
5.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: ff89ba41-3aa1-4d27-914a-91399e9639e5 (Secondary)

Description

In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.

Affected (15)

1 product
Mariadb
2 products
Aurora Mysql
Relational Database Service
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Mariadb
Up to 10.6.24
From 10.7.0 to 10.11.15
From 11.0.0 to 11.4.9
From 11.5.0 to 11.8.5
Configuration B
11 vulnerable
Vulnerable SoftwareAffected Versions
Amazon
Up to 2.12.5
From 3.01.0 to 3.04.5
From 3.05.1 to 3.10.2
Version 3.11.0
Amazon
Up to 10.6.24
From 10.11.4 to 10.11.15
From 11.4.3 to 11.4.9
From 11.8.3 to 11.8.5
Up to 5.7.44-rds.20251212
From 8.0.11 to 8.0.44
From 8.4.3 to 8.4.7

References (3)

Timeline

No history available yet.