Command Injection Vulnerability in MariaDB Server Due to Improper Input Sanitization
CVE-2026-44170
6.3MEDIUM
What is CVE-2026-44170?
A command injection vulnerability exists in MariaDB Server due to improper sanitization of user input when the CONNECT engine with REST support is enabled. This flaw affects various versions of MariaDB on Windows, allowing malicious users to inject and execute arbitrary shell commands through crafted table attributes. The issue has been addressed in updated versions, highlighting the importance of upgrading to maintain server integrity and security.
Affected Version(s)
server >= 10.6.1, < 10.6.26 < 10.6.1, 10.6.26
server >= 10.11.1, < 10.11.17 < 10.11.1, 10.11.17
server >= 11.4.1, < 11.4.11 < 11.4.1, 11.4.11
