Description

In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.

INFO

Published Date :

2026-03-03T18:12:12.361Z

Last Modified :

2026-03-16T17:03:08.613Z

Source :

AMZN
AFFECTED PRODUCTS

The following products are affected by CVE-2026-3494 vulnerability.

Vendors Products
Amazon
  • Aurora
  • Aurora Mysql
  • Rds For Mariadb
  • Rds For Mysql
  • Relational Database Service
Mariadb
  • Mariadb

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact