CVE-2026-3494
EUVD-2026-931103.03.2026, 20:16
In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mariadb | mariadb | 𝑥 ≤ 10.6.24 |
| mariadb | mariadb | 10.7.0 ≤ 𝑥 ≤ 10.11.15 |
| mariadb | mariadb | 11.0.0 ≤ 𝑥 ≤ 11.4.9 |
| mariadb | mariadb | 11.5.0 ≤ 𝑥 ≤ 11.8.5 |
| amazon | aurora_mysql | 𝑥 ≤ 2.12.5 |
| amazon | aurora_mysql | 3.01.0 ≤ 𝑥 ≤ 3.04.5 |
| amazon | aurora_mysql | 3.05.1 ≤ 𝑥 ≤ 3.10.2 |
| amazon | aurora_mysql | 3.11.0 |
| amazon | relational_database_service | 𝑥 ≤ 5.7.44-rds.20251212 |
| amazon | relational_database_service | 𝑥 ≤ 10.6.24 |
| amazon | relational_database_service | 8.0.11 ≤ 𝑥 ≤ 8.0.44 |
| amazon | relational_database_service | 8.4.3 ≤ 𝑥 ≤ 8.4.7 |
| amazon | relational_database_service | 10.11.4 ≤ 𝑥 ≤ 10.11.15 |
| amazon | relational_database_service | 11.4.3 ≤ 𝑥 ≤ 11.4.9 |
| amazon | relational_database_service | 11.8.3 ≤ 𝑥 ≤ 11.8.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration