Vulnerability Description
MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mariadb | Mariadb | >= 11.4.1, < 11.4.11 |
Related Weaknesses (CWE)
References
- https://github.com/MariaDB/server/security/advisories/GHSA-22xq-vq3f-87x2Vendor Advisory
- https://jira.mariadb.org/browse/MDEV-39288Issue Tracking
FAQ
What is CVE-2026-44169?
CVE-2026-44169 is a vulnerability with a CVSS score of 4.3 (MEDIUM). MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role,...
How severe is CVE-2026-44169?
CVE-2026-44169 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-44169?
Check the references section above for vendor advisories and patch information. Affected products include: Mariadb Mariadb.