SQL Injection Vulnerability in MariaDB Server by MariaDB Corporation
CVE-2026-44173

5MEDIUM

Key Information:

Vendor

Mariadb

Status
Vendor
CVE Published:
12 June 2026

What is CVE-2026-44173?

A vulnerability in the MariaDB server allows for SQL injection through the use of SELECT ... INTO OUTFILE and SELECT ... INTO DUMPFILE commands. This issue arises when the FROM clause contains only subqueries, which bypass the essential FILE privilege verification. As a result, an attacker could exploit this flaw to gain unauthorized access to sensitive data stored on the affected server. For proper protection, users are advised to upgrade to fixed versions: 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.

Affected Version(s)

server >= 10.6.1, < 10.6.26 < 10.6.1, 10.6.26

server >= 10.11.1, < 10.11.17 < 10.11.1, 10.11.17

server >= 11.4.1, < 11.4.11 < 11.4.1, 11.4.11

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.