CVE-2026-44173
published 2026-06-12CVE-2026-44173: MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11…
PriorityP431medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.40%
32.1th percentile
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB allowed SELECT ... INTO OUTFILE and SELECT ... INTO DUMPFILE without verifying the FILE privilege if the FROM clause contained only subqueries. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mariadb | mariadb | — | — |
| mariadb | mariadb | — | — |
| mariadb | mariadb | >= 10.11.1 < 10.11.17 | 10.11.17 |
| mariadb | mariadb | >= 10.6.1 < 10.6.26 | 10.6.26 |
| mariadb | mariadb | >= 11.4.1 < 11.4.11 | 11.4.11 |
| mariadb | mariadb | >= 11.8.1 < 11.8.7 | 11.8.7 |
| mariadb | server | — | — |
| mariadb | server | — | — |
| mariadb | server | — | — |
| mariadb | server | — | — |
| mariadb | server | — | — |
| mariadb_10.11 | mariadb | — | — |
| mariadb_11.8 | mariadb | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
MariaDB Server up to 12.3.1 authorization (GHSA-667j-m53j-wpmc)
vuldb·2026-06-12·CVSS 5.0
CVE-2026-44173 [MEDIUM] MariaDB Server up to 12.3.1 authorization (GHSA-667j-m53j-wpmc)
A vulnerability was found in MariaDB Server up to 10.6.25/10.11.16/11.4.10/11.8.6/12.3.1. It has been rated as problematic. Affected is an unknown function. This manipulation causes incorrect authorization.
The identification of this vulnerability is CVE-2026-44173. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
Red Hat
mariadb: MariaDB: Privilege bypass allows unauthorized file write via subqueries
vendor_redhat·2026-06-12·CVSS 5.3
CVE-2026-44173 [MEDIUM] CWE-266 mariadb: MariaDB: Privilege bypass allows unauthorized file write via subqueries
mariadb: MariaDB: Privilege bypass allows unauthorized file write via subqueries
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB allowed SELECT ... INTO OUTFILE and SELECT ... INTO DUMPFILE without verifying the FILE privilege if the FROM clause contained only subqueries. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.
A flaw was found in MariaDB server. This vulnerability allows a low-privileged authenticated user to bypass a security control that normally restricts file operations. Specifically, the system failed to verify the necessary 'FILE' privilege when certain 'SELECT' statements, which wri
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-44173 mariadb11.8: MariaDB: Privilege bypass allows unauthorized file write via subqueries [fedora-all]
bugzilla·2026-06-30·CVSS 5.3
CVE-2026-44173 [MEDIUM] CVE-2026-44173 mariadb11.8: MariaDB: Privilege bypass allows unauthorized file write via subqueries [fedora-all]
CVE-2026-44173 mariadb11.8: MariaDB: Privilege bypass allows unauthorized file write via subqueries [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB allowed SELECT ... INTO OUTFILE and SELECT ... INTO DUMPFILE without verifying the FILE privilege if the FROM clause contained only subqueries. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.
Discussion:
Fixed in the v
Bugzilla
CVE-2026-44173 mariadb10.11: MariaDB: Privilege bypass allows unauthorized file write via subqueries [fedora-all]
bugzilla·2026-06-30·CVSS 5.3
CVE-2026-44173 [MEDIUM] CVE-2026-44173 mariadb10.11: MariaDB: Privilege bypass allows unauthorized file write via subqueries [fedora-all]
CVE-2026-44173 mariadb10.11: MariaDB: Privilege bypass allows unauthorized file write via subqueries [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB allowed SELECT ... INTO OUTFILE and SELECT ... INTO DUMPFILE without verifying the FILE privilege if the FROM clause contained only subqueries. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.
Discussion:
Fixed in the
Bugzilla
CVE-2026-44173 mariadb: MariaDB: Privilege bypass allows unauthorized file write via subqueries
bugzilla·2026-06-12·CVSS 5.3
CVE-2026-44173 [MEDIUM] CVE-2026-44173 mariadb: MariaDB: Privilege bypass allows unauthorized file write via subqueries
CVE-2026-44173 mariadb: MariaDB: Privilege bypass allows unauthorized file write via subqueries
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB allowed SELECT ... INTO OUTFILE and SELECT ... INTO DUMPFILE without verifying the FILE privilege if the FROM clause contained only subqueries. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.
https://github.com/MariaDB/server/security/advisories/GHSA-667j-m53j-wpmchttps://jira.mariadb.org/browse/MDEV-39493https://access.redhat.com/errata/RHSA-2026:25143https://access.redhat.com/errata/RHSA-2026:25145https://access.redhat.com/errata/RHSA-2026:33093https://access.redhat.com/errata/RHSA-2026:33412https://access.redhat.com/errata/RHSA-2026:33464https://access.redhat.com/errata/RHSA-2026:33481https://access.redhat.com/errata/RHSA-2026:33482https://access.redhat.com/security/cve/CVE-2026-44173https://bugzilla.redhat.com/show_bug.cgi?id=2488460https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44173.json
2026-06-12
Published