CVE-2026-3494

EUVD-2026-9311
In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
mariadbmariadb
𝑥
≤ 10.6.24
mariadbmariadb
10.7.0 ≤
𝑥
≤ 10.11.15
mariadbmariadb
11.0.0 ≤
𝑥
≤ 11.4.9
mariadbmariadb
11.5.0 ≤
𝑥
≤ 11.8.5
amazonaurora_mysql
𝑥
≤ 2.12.5
amazonaurora_mysql
3.01.0 ≤
𝑥
≤ 3.04.5
amazonaurora_mysql
3.05.1 ≤
𝑥
≤ 3.10.2
amazonaurora_mysql
3.11.0
amazonrelational_database_service
𝑥
≤ 5.7.44-rds.20251212
amazonrelational_database_service
𝑥
≤ 10.6.24
amazonrelational_database_service
8.0.11 ≤
𝑥
≤ 8.0.44
amazonrelational_database_service
8.4.3 ≤
𝑥
≤ 8.4.7
amazonrelational_database_service
10.11.4 ≤
𝑥
≤ 10.11.15
amazonrelational_database_service
11.4.3 ≤
𝑥
≤ 11.4.9
amazonrelational_database_service
11.8.3 ≤
𝑥
≤ 11.8.5
𝑥
= Vulnerable software versions