CVE-2026-44169

Source
https://cve.org/CVERecord?id=CVE-2026-44169
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44169.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-44169
Aliases
Downstream
ALPINE (1)
BELL (1)
CGA (1)
DEBIAN (1)
ECHO (1)
MGASA (1)
MINI (4)
openSUSE (2)
RHSA (4)
RLSA (4)
ROOT (2)
SUSE (2)
UBUNTU (1)
Related
Published
2026-06-12T17:31:53Z
Modified
2026-08-12T03:51:28Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
MariaDB: Authorization bypass in role-based routine-level privilege check exposes stored routine definitions
Details

MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-863"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44169.json"
}
References

Affected packages

Git / github.com/mariadb/server

Affected ranges

Type
GIT
Repo
https://github.com/mariadb/server
Events
Database specific
Show details
{
    "cpe":  [
        "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:mariadb:mariadb:12.3.1:*:*:*:*:*:*:*"
    ],
    "extracted_events":  [
        {
            "introduced":  "11.4.1"
        },
        {
            "fixed":  "11.4.11"
        },
        {
            "introduced":  "11.8.1"
        },
        {
            "fixed":  "11.8.7"
        },
        {
            "introduced":  "12.3.1"
        },
        {
            "last_affected":  "12.3.1"
        }
    ],
    "source":  [
        "CPE_RANGE",
        "CPE_STRING"
    ]
}

Affected versions

12.*
12.3.1
mariadb-11.*
mariadb-11.4.1
mariadb-11.4.10
mariadb-11.4.11
mariadb-11.4.2
mariadb-11.4.3
mariadb-11.4.4
mariadb-11.4.5
mariadb-11.4.6
mariadb-11.4.7
mariadb-11.4.8
mariadb-11.4.9
mariadb-11.8.1
mariadb-11.8.2
mariadb-11.8.3
mariadb-11.8.4
mariadb-11.8.6
mariadb-11.8.7
mariadb-12.*
mariadb-12.3.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44169.json"