Incorrect authorization in MariaDB - CVE-2026-44173
Published: May 19, 2026
MariaDB
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to incorrect authorization in SELECT ... INTO OUTFILE and SELECT ... INTO DUMPFILE handling when processing queries whose FROM clause contains only subqueries. A remote user can execute a crafted query to cause a denial of service.
The issue occurs because the FILE privilege is not verified in this query pattern.