CVE-2026-3494

In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*
cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*
cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*
cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:amazon:aurora_mysql:*:*:*:*:*:*:*:*
cpe:2.3:a:amazon:aurora_mysql:*:*:*:*:*:*:*:*
cpe:2.3:a:amazon:aurora_mysql:*:*:*:*:*:*:*:*
cpe:2.3:a:amazon:aurora_mysql:3.11.0:*:*:*:*:*:*:*
cpe:2.3:a:amazon:relational_database_service:*:*:*:*:*:mysql:*:*
cpe:2.3:a:amazon:relational_database_service:*:*:*:*:*:mariadb:*:*
cpe:2.3:a:amazon:relational_database_service:*:*:*:*:*:mysql:*:*
cpe:2.3:a:amazon:relational_database_service:*:*:*:*:*:mysql:*:*
cpe:2.3:a:amazon:relational_database_service:*:*:*:*:*:mariadb:*:*
cpe:2.3:a:amazon:relational_database_service:*:*:*:*:*:mariadb:*:*
cpe:2.3:a:amazon:relational_database_service:*:*:*:*:*:mariadb:*:*

History

No history.

Information

Published : 2026-03-03 20:16

Updated : 2026-03-16 18:16


NVD link : CVE-2026-3494

Mitre link : CVE-2026-3494

CVE.ORG link : CVE-2026-3494


JSON object : View

Products Affected

amazon

  • relational_database_service
  • aurora_mysql

mariadb

  • mariadb
CWE
CWE-778

Insufficient Logging

NVD-CWE-noinfo