CVE 10 CRITICAL

MariaDB server has unsafe parameter handling in `wsrep_notify_cmd`_CVE-2026-49261

10 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Description

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.

AI Analysis

The MariaDB server has a vulnerability in the `wsrep_notify_cmd` that allows the execution of shell commands embedded in the name of the joiner node.

Basic Information

ID CVE-2026-49261
Source GitHub_M
Published Jun 11, 2026 at 17:13
Modified Jun 11, 2026 at 18:20

Affected Product

Vendor MariaDB
Product server
Version >= 10.6.1, < 10.6.27
Affected Versions MariaDB server >= 10.6.1, < 10.6.27
MariaDB server >= 10.11.1, < 10.11.18
MariaDB server >= 11.4.1, < 11.4.12
MariaDB server >= 11.8.1, < 11.8.8
MariaDB server = 12.3.1

CWE Classification

AI Assessment

AI Score 10 / 10
AI Severity Critical
Vendor MariaDB
Product MariaDB Server
Version 10.6.1-10.6.26, 10.11.1-10.11.17, 11.4.1-11.4.11, 11.8.1-11.8.7, 12.3.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.