Executive brief
MariaDB is a widely used database system for storing and managing business data. A security flaw in the Windows version of the software allows an attacker to execute unauthorized commands on the server hosting the database. This could lead to a full system compromise, data theft, or disruption of database services.
Technical details
An OS command injection vulnerability (CWE-78) exists in MariaDB for Windows when using the CONNECT storage engine with REST support enabled. The vulnerability stems from the improper sanitization of the table HTTP attribute before it is interpolated into a 'curl' command line string. Specifically, the software uses sprintf to construct a command for CreateProcess without escaping the URL input. An attacker can exploit this to inject additional shell commands that will be executed with the privileges of the MariaDB service. The issue is fixed in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.
Affected products
- MariaDB MariaDB Server 10.6.1 to 10.6.25, 10.11.1 to 10.11.16, 11.4.1 to 11.4.10, 11.8.1 to 11.8.6, 12.3.1
Timeline
- 2026-04-08: other: Issue reported to MariaDB Jira
- 2026-04-12: patched: Issue resolved in source code
- 2026-05-18: advisory: GitHub security advisory published
- 2026-06-12: disclosed: CVE published to NVD