Unrated severityNVD Advisory· Published Mar 3, 2026· Updated Mar 16, 2026
MariaDB Server Audit Plugin Comment Handling Bypass
CVE-2026-3494
Description
In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.
Affected products
4- Amazon/Aurora MySQLv5Range: 2.12.6
- Amazon/RDS for MariaDBv5Range: 10.6.25
- Amazon/RDS for MySQLv5Range: 5.7.44-RDS.20260212
- MariaDB Foundation/MariaDB Serverv5Range: 10.6.25
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.