CVE-2026-3494
MariaDB Server Audit Plugin Comment Handling Bypass
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (โ) or hash (#) style comments, the statement is not logged.
| CWE | CWE-778 |
| Vendor | mariadb foundation |
| Product | mariadb server |
| Published | Mar 3, 2026 |
| Last Updated | Mar 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for mariadb foundation mariadb server
Be the first to know when new medium vulnerabilities affecting mariadb foundation mariadb server are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Affected Versions
MariaDB Foundation / MariaDB Server
All versions affected Amazon / Aurora MySQL
All versions affected Amazon / RDS for MySQL
All versions affected Amazon / RDS for MariaDB
All versions affected