CVE-2026-44169
published 2026-06-12CVE-2026-44169: MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting…
PriorityP424medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.16%
5.7th percentile
MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mariadb | mariadb | — | — |
| mariadb | server | — | — |
| mariadb | server | — | — |
| mariadb | server | — | — |
| mariadb_10.11 | mariadb | — | — |
| mariadb_11.8 | mariadb | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
MariaDB Server up to 11.4.10/11.8.6/12.3.1 authorization (GHSA-22xq-vq3f-87x2)
vuldb·2026-06-12·CVSS 4.3
CVE-2026-44169 [MEDIUM] MariaDB Server up to 11.4.10/11.8.6/12.3.1 authorization (GHSA-22xq-vq3f-87x2)
A vulnerability has been found in MariaDB Server up to 11.4.10/11.8.6/12.3.1 and classified as problematic. The affected element is an unknown function. Performing a manipulation results in incorrect authorization.
This vulnerability is known as CVE-2026-44169. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
Red Hat
mariadb: MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check
vendor_redhat·2026-06-12·CVSS 4.3
CVE-2026-44169 [MEDIUM] CWE-266 mariadb: MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check
mariadb: MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check
MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2.
A flaw was found in MariaDB server. A user who has been granted EXECUTE access to a stored routine through a role can view the definition of that routine. This information disclosure occurs even if the user does not possess the `SHOW CREATE ROUTINE` privilege, potentially exposing sensitive routine logic. This vulnerability allows for
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-44169 mariadb11.8: MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check [fedora-all]
bugzilla·2026-06-30·CVSS 4.3
CVE-2026-44169 [MEDIUM] CVE-2026-44169 mariadb11.8: MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check [fedora-all]
CVE-2026-44169 mariadb11.8: MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2.
Discussion:
Fixed in the version currently available in Fedora Rawhide
Bugzilla
CVE-2026-44169 mariadb10.11: MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check [fedora-all]
bugzilla·2026-06-30·CVSS 4.3
CVE-2026-44169 [MEDIUM] CVE-2026-44169 mariadb10.11: MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check [fedora-all]
CVE-2026-44169 mariadb10.11: MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2.
Discussion:
Not applicable to 10.11 version:
https://github.com/MariaDB/server
Bugzilla
CVE-2026-44169 mariadb: MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check
bugzilla·2026-06-12·CVSS 4.3
CVE-2026-44169 [MEDIUM] CVE-2026-44169 mariadb: MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check
CVE-2026-44169 mariadb: MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check
MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2.
2026-06-12
Published