SQL Injection Vulnerability in MariaDB Server by MariaDB Corporation
CVE-2026-44173
5MEDIUM
What is CVE-2026-44173?
A vulnerability in the MariaDB server allows for SQL injection through the use of SELECT ... INTO OUTFILE and SELECT ... INTO DUMPFILE commands. This issue arises when the FROM clause contains only subqueries, which bypass the essential FILE privilege verification. As a result, an attacker could exploit this flaw to gain unauthorized access to sensitive data stored on the affected server. For proper protection, users are advised to upgrade to fixed versions: 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.
Affected Version(s)
server >= 10.6.1, < 10.6.26 < 10.6.1, 10.6.26
server >= 10.11.1, < 10.11.17 < 10.11.1, 10.11.17
server >= 11.4.1, < 11.4.11 < 11.4.1, 11.4.11
