FAIL › dossier
mariadb
VENDOR· dossier confidence 60%
MariaDB is an open-source database fork with a critical security track record, evidenced by multiple RCE0day vulnerabilities in June 2026 affecting major version ranges. The foundation relies on community sponsorship rather than corporate ownership.
PROFILE
Categoryopen-source database softwareWhat they doMariaDB is a community-developed fork of MySQL providing a general-purpose relational database management system with pluggable architecture and high availability features.Founded2009Ownershipfoundation
Websitehttps://mariadb.org ↗
SECURITY POSTURE
Critical vulnerabilities (RCE0day) were identified in multiple major version ranges (10.6.x, 11.4.x, 11.8.x, 12.x) in June 2026, indicating significant gaps in patch management or release cadence for critical security fixes.
Notable failures
- CVE-2026-44170: Critical RCE0day in versions 10.6.1-10.6.26, 10.11.1-10.11.17, 11.4.1-11.4.11, 11.8.1-11.8.7
- CVE-2026-49261: Critical RCE in versions 10.6.1-10.6.26, 10.11.1-10.11.17, 11.4.1-11.4.11, 11.8.1-11.8.7, 12.x
- CVE-2026-44172: Critical vulnerability in versions 3.3.18 and 3.4.8 involving non-validated user input
Patterns: Repeated critical RCE vulnerabilities across multiple major version ranges; Wide version range exposure for critical fixes
FAILURE HISTORY · 6
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-06-12 | CVE-2026-44170 | critical | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB on WIndows with installed CONNECT engine and enabled REST support interpolated |
| 2026-06-12 | CVE-2026-44170 | critical | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB on WIndows with installed CONNECT engine and enabled REST support interpolated |
| 2026-06-11 | CVE-2026-49261 | critical | MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node |
| 2026-06-11 | CVE-2026-49261 | critical | MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node |
| 2026-06-12 | CVE-2026-44172 | critical | MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerabl |
| 2026-06-12 | CVE-2026-44172 | critical | MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerabl |
DOSSIER SOURCES
- MariaDB - Wikipedia · en.wikipedia.org
- MongoDB (MDB) Company Profile & Description - Stock Analysis · stockanalysis.com
- Company Database Search · www.edgarcompany.sec.gov
- Announcements Archives - MariaDB.org · mariadb.org
- Base Package: mingw-w64-mariadb-clients - MSYS2 Packages · packages.msys2.org
- CVEdata.com - The State of Software Vulnerabilities · cvedata.com
- Critical Vulnerabilities 2026: NIS2 & DORA Compliance Guide | AIGovHub · www.aigovhub.io
- Base Package: mingw-w64-mariadb-clients - MSYS2 Packages · packages.msys2.org
Open questions: MariaDB Foundation's patch management process for critical vulnerabilities · Commercial support availability for enterprise customers
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-30 03:51:12.647764+00:00