Vulnerability Description
In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mariadb | Mariadb | <= 10.6.24 |
| Amazon | Aurora Mysql | <= 2.12.5 |
| Amazon | Relational Database Service | <= 5.7.44-rds.20251212 |
Related Weaknesses (CWE)
References
- https://aws.amazon.com/security/security-bulletins/2026-006-AWS/Third Party Advisory
- https://github.com/MariaDB/server/commit/635559a2ad68a5a6d1a354e8209c58323dba026
- https://github.com/aws/audit-plugin-for-mysql/commit/01e25a5cb1073f131eea774c06c
FAQ
What is CVE-2026-3494?
CVE-2026-3494 is a vulnerability with a CVSS score of 4.3 (MEDIUM). In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated databa...
How severe is CVE-2026-3494?
CVE-2026-3494 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-3494?
Check the references section above for vendor advisories and patch information. Affected products include: Mariadb Mariadb, Amazon Aurora Mysql, Amazon Relational Database Service.