CVE-2026-3494

In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*
cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*
cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*
cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:amazon:aurora_mysql:*:*:*:*:*:*:*:*
cpe:2.3:a:amazon:aurora_mysql:*:*:*:*:*:*:*:*
cpe:2.3:a:amazon:aurora_mysql:*:*:*:*:*:*:*:*
cpe:2.3:a:amazon:aurora_mysql:3.11.0:*:*:*:*:*:*:*
cpe:2.3:a:amazon:relational_database_service:*:*:*:*:*:mysql:*:*
cpe:2.3:a:amazon:relational_database_service:*:*:*:*:*:mariadb:*:*
cpe:2.3:a:amazon:relational_database_service:*:*:*:*:*:mysql:*:*
cpe:2.3:a:amazon:relational_database_service:*:*:*:*:*:mysql:*:*
cpe:2.3:a:amazon:relational_database_service:*:*:*:*:*:mariadb:*:*
cpe:2.3:a:amazon:relational_database_service:*:*:*:*:*:mariadb:*:*
cpe:2.3:a:amazon:relational_database_service:*:*:*:*:*:mariadb:*:*

History

09 Mar 2026, 18:12

Type Values Removed Values Added
References () https://aws.amazon.com/security/security-bulletins/2026-006-AWS/ - () https://aws.amazon.com/security/security-bulletins/2026-006-AWS/ - Third Party Advisory
Summary
  • (es) En la versión del servidor MariaDB hasta la 11.8.5, cuando el plugin de auditoría del servidor está habilitado con la variable server_audit_events configurada con el filtrado QUERY_DCL, QUERY_DDL o QUERY_DML, si un usuario de base de datos autenticado invoca una instrucción SQL prefijada con comentarios estilo doble guion (—) o almohadilla (#), la instrucción no se registra.
CPE cpe:2.3:a:amazon:aurora_mysql:3.11.0:*:*:*:*:*:*:*
cpe:2.3:a:amazon:relational_database_service:*:*:*:*:*:mariadb:*:*
cpe:2.3:a:amazon:aurora_mysql:*:*:*:*:*:*:*:*
cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*
cpe:2.3:a:amazon:relational_database_service:*:*:*:*:*:mysql:*:*
First Time Mariadb mariadb
Amazon aurora Mysql
Amazon relational Database Service
Mariadb
Amazon
CWE NVD-CWE-noinfo

03 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-03 20:16

Updated : 2026-03-09 18:12


NVD link : CVE-2026-3494

Mitre link : CVE-2026-3494

CVE.ORG link : CVE-2026-3494


JSON object : View

Products Affected

mariadb

  • mariadb

amazon

  • aurora_mysql
  • relational_database_service
CWE
CWE-778

Insufficient Logging

NVD-CWE-noinfo