CVE-2026-44169

MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*
cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*
cpe:2.3:a:mariadb:mariadb:12.3.1:*:*:*:*:*:*:*

History

17 Jun 2026, 16:24

Type Values Removed Values Added
References () https://github.com/MariaDB/server/security/advisories/GHSA-22xq-vq3f-87x2 - () https://github.com/MariaDB/server/security/advisories/GHSA-22xq-vq3f-87x2 - Vendor Advisory
References () https://jira.mariadb.org/browse/MDEV-39288 - () https://jira.mariadb.org/browse/MDEV-39288 - Issue Tracking
CPE cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*
cpe:2.3:a:mariadb:mariadb:12.3.1:*:*:*:*:*:*:*
First Time Mariadb mariadb
Mariadb

12 Jun 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-12 18:16

Updated : 2026-06-17 16:24


NVD link : CVE-2026-44169

Mitre link : CVE-2026-44169

CVE.ORG link : CVE-2026-44169


JSON object : View

Products Affected

mariadb

  • mariadb
CWE
CWE-863

Incorrect Authorization