CVE-2026-3494
Published: Mar 3, 2026
Modified: Mar 16, 2026
CVSS v3.1
4.3
Description
In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.
| Vendor | Product | Versions |
|---|---|---|
MariaDB Foundation | MariaDB Server | unaffected 10.6.25unaffected 10.11.16unaffected 11.4.10unaffected 11.8.6 |
Amazon | Aurora MySQL | unaffected 2.12.6unaffected 3.04.6unaffected 3.10.3unaffected 3.11.1 |
Amazon | RDS for MySQL | unaffected 5.7.44-RDS.20260212unaffected 8.0.45unaffected 8.4.8 |
Amazon | RDS for MariaDB | unaffected 10.6.25unaffected 10.11.16unaffected 11.4.10unaffected 11.8.6 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now