Command Injection Vulnerability in MariaDB Server Due to Improper Input Sanitization
CVE-2026-44170

6.3MEDIUM

Key Information:

Vendor

Mariadb

Status
Vendor
CVE Published:
12 June 2026

What is CVE-2026-44170?

A command injection vulnerability exists in MariaDB Server due to improper sanitization of user input when the CONNECT engine with REST support is enabled. This flaw affects various versions of MariaDB on Windows, allowing malicious users to inject and execute arbitrary shell commands through crafted table attributes. The issue has been addressed in updated versions, highlighting the importance of upgrading to maintain server integrity and security.

Affected Version(s)

server >= 10.6.1, < 10.6.26 < 10.6.1, 10.6.26

server >= 10.11.1, < 10.11.17 < 10.11.1, 10.11.17

server >= 11.4.1, < 11.4.11 < 11.4.1, 11.4.11

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.