MEDIUM · 4.3

CVE-2026-3494

In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated databa...

Vulnerability Description

In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.

CVSS Score

4.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
MariadbMariadb<= 10.6.24
AmazonAurora Mysql<= 2.12.5
AmazonRelational Database Service<= 5.7.44-rds.20251212

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-3494?

CVE-2026-3494 is a vulnerability with a CVSS score of 4.3 (MEDIUM). In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated databa...

How severe is CVE-2026-3494?

CVE-2026-3494 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2026-3494?

Check the references section above for vendor advisories and patch information. Affected products include: Mariadb Mariadb, Amazon Aurora Mysql, Amazon Relational Database Service.