MariaDB: Argument injection in CONNECT REST Xcurl on Windows via unsanitized URL
CVE-2026-44170

6.3MEDIUM

Key Information:

Vendor

Mariadb

Status
Vendor
CVE Published:
12 June 2026

What is CVE-2026-44170?

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB on WIndows with installed CONNECT engine and enabled REST support interpolated table HTTP attribute into the curl command line without proper sanitizing. This allows the user to execute shell commands on the server. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.

Affected Version(s)

server >= 10.6.1, < 10.6.26 < 10.6.1, 10.6.26

server >= 10.11.1, < 10.11.17 < 10.11.1, 10.11.17

server >= 11.4.1, < 11.4.11 < 11.4.1, 11.4.11

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.