Junglewise Threat Intelligence

CVE-2026-3494: MariaDB and Amazon RDS audit log bypass via SQL comment prefixing

CVE-2026-3494 · Severity: high · CVSS 4.3 · Published 2026-03-03

Technologies: MariaDB Foundation MariaDB Server, Amazon AWS. Vendors: MariaDB Foundation, Amazon, Amazon Web Services.

Executive brief

A vulnerability in the MariaDB and Amazon RDS/Aurora audit logging system allows authenticated users to bypass activity monitoring. By adding specific comment characters to the beginning of a database command, a user can execute actions that are not recorded in the security logs. This could allow malicious activity to go undetected by security teams relying on these logs for compliance or incident response.

Technical details

An insufficient logging vulnerability (CWE-778) exists in the MariaDB Server Audit Plugin and its derivatives used in Amazon RDS and Aurora. The issue stems from the audit plugin's internal SQL parser failing to correctly handle statements prefixed with double-hyphen (--) or hash (#) style comments when specific event filtering (QUERY_DCL, QUERY_DDL, or QUERY_DML) is enabled. An authenticated attacker can exploit this by prefixing their SQL commands with these comment strings, causing the server to execute the command without recording it in the audit log. This bypasses security auditing and compliance monitoring. The fix involves removing the plugin's custom parser in favor of the core server's SQL command handling.

Affected products

  • MariaDB Foundation MariaDB Server <= 10.6.24, 10.11.15, 11.4.9, 11.8.5
  • Amazon Aurora MySQL <= 2.12.5, 3.01.0 to 3.04.5, 3.05.1 to 3.10.2, 3.11.0
  • Amazon RDS for MySQL <= 5.7.44-RDS.20251212, 8.0.11 to 8.0.44, 8.4.3 to 8.4.7
  • Amazon RDS for MariaDB <= 10.6.24, 10.11.4 to 10.11.15, 11.4.3 to 11.4.9, 11.8.3 to 11.8.5

Timeline

  • 2026-03-03: disclosed
  • 2026-03-03: advisory: AWS Security Bulletin 2026-006-AWS published
  • 2026-03-03: patched

References

Related threats