CVE-2026-3494: Amazon Aurora MySQL

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.

Affected products

  • Amazon Aurora MySQL: up to and including 2.12.5; from 3.01.0, before 3.04.6 (fixed in 3.04.6); from 3.05.1, up to and including 3.10.2; version 3.11.0 only
  • Amazon Relational Database Service: up to and including 5.7.44-rds.20251212; up to and including 10.6.24; from 8.0.11, up to and including 8.0.44; from 8.4.3, up to and including 8.4.7; from 10.11.4, up to and including 10.11.15; from 11.4.3, up to and including 11.4.9; …
  • MariaDB MariaDB: up to and including 10.6.24; from 10.7.0, up to and including 10.11.15; from 11.0.0, up to and including 11.4.9; from 11.5.0, up to and including 11.8.5

Published 2026-03-03. Last modified 2026-07-14.