๐Ÿ” CVE Alert

CVE-2026-3494

MEDIUM 4.3

MariaDB Server Audit Plugin Comment Handling Bypass

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (โ€”) or hash (#) style comments, the statement is not logged.

CWE CWE-778
Vendor mariadb foundation
Product mariadb server
Published Mar 3, 2026
Last Updated Mar 16, 2026
Stay Ahead of the Next One

Get instant alerts for mariadb foundation mariadb server

Be the first to know when new medium vulnerabilities affecting mariadb foundation mariadb server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

MariaDB Foundation / MariaDB Server
All versions affected
Amazon / Aurora MySQL
All versions affected
Amazon / RDS for MySQL
All versions affected
Amazon / RDS for MariaDB
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
aws.amazon.com: https://aws.amazon.com/security/security-bulletins/2026-006-AWS/ github.com: https://github.com/MariaDB/server/commit/635559a2ad68a5a6d1a354e8209c58323dba0261 github.com: https://github.com/aws/audit-plugin-for-mysql/commit/01e25a5cb1073f131eea774c06c8a056b1e4b2ff