CVE-2026-44170
MariaDB: Argument injection in CONNECT REST Xcurl on Windows via unsanitized URL
CVSS Score
9.9
EPSS Score
0.0%
EPSS Percentile
0th
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB on WIndows with installed CONNECT engine and enabled REST support interpolated table HTTP attribute into the curl command line without proper sanitizing. This allows the user to execute shell commands on the server. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.
| CWE | CWE-78 |
| Vendor | mariadb |
| Product | server |
| Published | Jun 12, 2026 |
| Last Updated | Jul 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for mariadb server
Be the first to know when new critical vulnerabilities affecting mariadb server are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
MariaDB / server
>= 10.6.1, < 10.6.26 >= 10.11.1, < 10.11.17 >= 11.4.1, < 11.4.11 >= 11.8.1, < 11.8.7 >= 12.3.1, < 12.3.2
References
github.com: https://github.com/MariaDB/server/security/advisories/GHSA-f835-cfjq-wf73 jira.mariadb.org: https://jira.mariadb.org/browse/MDEV-39289 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-44170 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2488451 security.access.redhat.com: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44170.json access.redhat.com: https://access.redhat.com/errata/RHSA-2026:33093 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:33412 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:33464 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:33482 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:33481 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:25145 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:25143