# CVE-2026-3494

## Summary

- **CVE ID:** CVE-2026-3494
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-778
- **Published:** Mar 3, 2026
- **Last Modified:** Mar 16, 2026

## Description

In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.

## Affected Products

- MariaDB Foundation — MariaDB Server (10.6.25)
- MariaDB Foundation — MariaDB Server (10.11.16)
- MariaDB Foundation — MariaDB Server (11.4.10)
- MariaDB Foundation — MariaDB Server (11.8.6)
- Amazon — Aurora MySQL (2.12.6)
- Amazon — Aurora MySQL (3.04.6)
- Amazon — Aurora MySQL (3.10.3)
- Amazon — Aurora MySQL (3.11.1)
- Amazon — RDS for MySQL (5.7.44-RDS.20260212)
- Amazon — RDS for MySQL (8.0.45)
- Amazon — RDS for MySQL (8.4.8)
- Amazon — RDS for MariaDB (10.6.25)
- Amazon — RDS for MariaDB (10.11.16)
- Amazon — RDS for MariaDB (11.4.10)
- Amazon — RDS for MariaDB (11.8.6)

## References

- [CNA](https://aws.amazon.com/security/security-bulletins/2026-006-AWS/)
- [CNA](https://github.com/MariaDB/server/commit/635559a2ad68a5a6d1a354e8209c58323dba0261)
- [CNA](https://github.com/aws/audit-plugin-for-mysql/commit/01e25a5cb1073f131eea774c06c8a056b1e4b2ff)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.27%
- **EPSS Percentile:** 19.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._