Vulnerability Description
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB allowed SELECT ... INTO OUTFILE and SELECT ... INTO DUMPFILE without verifying the FILE privilege if the FROM clause contained only subqueries. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mariadb | Mariadb | >= 10.6.1, < 10.6.26 |
Related Weaknesses (CWE)
References
- https://github.com/MariaDB/server/security/advisories/GHSA-667j-m53j-wpmcVendor Advisory
- https://jira.mariadb.org/browse/MDEV-39493Issue TrackingThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:25143
- https://access.redhat.com/errata/RHSA-2026:25145
- https://access.redhat.com/errata/RHSA-2026:33093
- https://access.redhat.com/errata/RHSA-2026:33412
- https://access.redhat.com/errata/RHSA-2026:33464
- https://access.redhat.com/errata/RHSA-2026:33481
- https://access.redhat.com/errata/RHSA-2026:33482
- https://access.redhat.com/errata/RHSA-2026:49522
- https://access.redhat.com/security/cve/CVE-2026-44173
- https://bugzilla.redhat.com/show_bug.cgi?id=2488460
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44173.json
FAQ
What is CVE-2026-44173?
CVE-2026-44173 is a vulnerability with a CVSS score of 5.0 (MEDIUM). MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB...
How severe is CVE-2026-44173?
CVE-2026-44173 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-44173?
Check the references section above for vendor advisories and patch information. Affected products include: Mariadb Mariadb.