MariaDB has multiple security flaws

Published September 11, 2026

MariaDB has a CERT-Bund advisory for 6 vulnerabilities in versions before 11.8.7. An attacker can exploit multiple vulnerabilities in MariaDB to carry out an unspecified attack.

Severity
Not scoredNo CVSS score recorded
Fix
Fixed in 11.8.7Fix recorded today
Affected versions
before 11.8.7
Affects
MariaDB+4 more
Exploited
Not confirmedNo confirmation recorded

How it works

An attacker can exploit multiple vulnerabilities in MariaDB to carry out an unspecified attack.

What to do

Check your MariaDB version. If it is before 11.8.7, this advisory applies.

Update MariaDB to 11.8.7 or newer.

Technical details

Affected software: MariaDB, Linux, Sonstiges, UNIX, Windows

CERT-Bund describes MariaDB as a relationales Datenbanksystem, das anwendungskompatibel mit MySQL ist. An attacker can exploit multiple vulnerabilities in MariaDB to carry out an unspecified attack. The advisory tracks CVE-2026-44168, CVE-2026-44169, CVE-2026-44170, CVE-2026-44171, CVE-2026-44172, CVE-2026-44173. In CERT-Bund's CSAF data, affected versions are before 11.8.7, before 11.4.11, before 10.11.17, before 10.6.26, and the fixed version is 11.8.7, 11.4.11, 10.11.17, 10.6.26.

Affected operating systems listed by CERT-Bund: Linux, Sonstiges, UNIX, Windows.

References