VYPR
Unrated severityNVD Advisory· Published Mar 3, 2026· Updated Mar 16, 2026

MariaDB Server Audit Plugin Comment Handling Bypass

CVE-2026-3494

Description

In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

13

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.