MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2.
Metrics
Affected Vendors & Products
References
History
Fri, 12 Jun 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mariadb
Mariadb server |
|
| Vendors & Products |
Mariadb
Mariadb server |
Fri, 12 Jun 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2. | |
| Title | MariaDB: Authorization bypass in role-based routine-level privilege check exposes stored routine definitions | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-12T17:31:53.344Z
Reserved: 2026-05-05T14:39:34.923Z
Link: CVE-2026-44169
No data.
Status : Received
Published: 2026-06-12T18:16:33.713
Modified: 2026-06-12T18:16:33.713
Link: CVE-2026-44169
No data.
OpenCVE Enrichment
Updated: 2026-06-12T20:00:18Z