CVE-2026-3494 affects MariaDB server versions up to 11.8.5, specifically when the server audit plugin is enabled with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering. An authenticated user can bypass logging of SQL statements by prefixing them with double-hyphen or hash comments. This vulnerability has a CVSS score of 4.3 (Medium), indicating a low complexity attack that could lead to a partial loss of integrity, as audit logs would be incomplete. There is no evidence of active exploitation, nor are there public exploit modules available in Metasploit or Nuclei, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.6.24CPE matchmatch criteria | cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* | ||
>= 10.7.0, <= 10.11.15CPE matchmatch criteria | cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* | ||
>= 11.0.0, <= 11.4.9CPE matchmatch criteria | cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* | ||
>= 11.5.0, <= 11.8.5CPE matchmatch criteria | cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* | ||
<= 2.12.5CPE matchmatch criteria | cpe:2.3:a:amazon:aurora_mysql:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.