CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-44170

Critical · CVSS 9.8

MariaDB server — OS Command Injection (CWE-78) via CONNECT engine REST/HTTP table attribute interpolated into curl command line

CVSS
9.8
nvd
EPSS
1.19%
65th pct
KEV
No
Class
oss containerizable
CWE-78, CWE-78

Description

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB on WIndows with installed CONNECT engine and enabled REST support interpolated table HTTP attribute into the curl command line without proper sanitizing. This allows the user to execute shell commands on the server. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.

Search profile — drives PoC discovery

Symbols CONNECTRESTcurlHTTPtable HTTP attributeMDEV-39289GHSA-f835-cfjq-wf73
Keywords CVE-2026-44170MariaDB CONNECT engine RCEMariaDB REST curl injectionMariaDB Windows shell injectionMariaDB CONNECT HTTP command injectionMDEV-39289GHSA-f835-cfjq-wf73MariaDB curl command line injection PoC
Versions: 10.6.1 to <10.6.26, 10.11.1 to <10.11.17, 11.4.1 to <11.4.11, 11.8.1 to <11.8.7, 12.3.1

Affected packages

Bitnami mariadb 10.11.1 → 10.11.17
Bitnami mariadb 10.6.1 → 10.6.26
Bitnami mariadb 11.4.1 → 11.4.11
Bitnami mariadb 11.8.1 → 11.8.7
Bitnami mariadb 12.3.1 → 12.3.2
Bitnami mariadb-min 10.11.1 → 10.11.17
Bitnami mariadb-min 10.6.1 → 10.6.26
Bitnami mariadb-min 11.4.1 → 11.4.11
Bitnami mariadb-min 11.8.1 → 11.8.7
Bitnami mariadb-min 12.3.1 → 12.3.2
Bitnami mysql-client 10.11.1 → 10.11.17
Bitnami mysql-client 10.6.1 → 10.6.26
Bitnami mysql-client 11.4.1 → 11.4.11
Bitnami mysql-client 11.8.1 → 11.8.7
Bitnami mysql-client 12.3.1 → 12.3.2

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T12:30:14.000Z