MariaDB Server through version 11.8.5 contains an audit-logging bypass in the server audit plugin. When the plugin is enabled and its event filter includes QUERY_DCL, QUERY_DDL, or QUERY_DML, an authenticated database user can prefix a SQL statement with a double-hyphen or hash-style comment to cause the statement to be omitted from the audit log.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a proof-of-concept verification environment for CVE-2026-3494, focused on demonstrating an audit logging bypass or omission in MariaDB's server_audit plugin rather than achieving code execution. The repository contains a Docker-based lab, MariaDB audit configuration, initialization SQL, a Python PoC, and captured execution results. Structure and purpose: - Dockerfile: builds a minimal Python 3.10 container that runs the PoC script. - docker-compose.yml: launches three MariaDB containers for comparative testing: 10.3.39 on port 3306, 11.8.5 on 3307, and 11.8.6 on 3308. - config/server_audit.cnf: enables server_audit, configures QUERY_DCL/QUERY_DDL/QUERY_DML logging, and writes logs to /var/lib/mysql/server_audit.log. - init/init.sql: installs/enables the audit plugin and creates a privileged test user (u01 / Test1234!). - poc/poc.py: main exploit/verification logic. - results/full_execution_log.md: evidence showing which queries were logged or omitted. Main exploit capability: The Python script connects over the network to each MariaDB instance using PyMySQL, executes a fixed set of SQL test cases, reads the corresponding audit log file from the host-mounted logs directory, extracts logged SQL statements with regex parsing, and determines whether each query was recorded. Its core capability is to reproduce and verify audit-log omission conditions. The notable cases are: - SELECT * FROM user; causing Error 1046 ('No database selected') - A multiline SET PASSWORD statement containing an inline # comment According to the included results, these are logged on 10.3.39 and 11.8.5 but not logged on 11.8.6, while normal SELECT and some other error/comment cases remain logged. This is not a detection-only script in the narrow sense; it actively performs the triggering actions against live MariaDB targets and validates the bypass outcome by inspecting audit logs. However, it does not deliver a post-exploitation payload, shell, or persistence mechanism. Its impact is security-control evasion: demonstrating that certain DCL/DML-related statements may evade audit visibility under specific parser/logging conditions. Notable implementation details: - TARGETS hardcode localhost endpoints and ports for three MariaDB versions. - LOG_PATHS map each target port to a host-side audit log file. - TEST_CASES define five scenarios, including normal queries, error-triggering queries, and comment-injected statements. - execute_query() runs the SQL and tolerates exceptions so failed queries can still be checked for logging behavior. - extract_sql() parses quoted SQL fragments from audit log entries. - test_target() compares pre/post log contents to isolate newly written entries and classify each test as LOGGED or NOT LOGGED. Overall, this repository is a reproducible lab and PoC for validating an audit logging bypass/regression in MariaDB server_audit across versions, with the primary target being MariaDB 11.8.6.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.