10
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Description
MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.
AI Analysis
The MariaDB server has a vulnerability in the `wsrep_notify_cmd` that allows the execution of shell commands embedded in the name of the joiner node.
Basic Information
ID
CVE-2026-49261
Source
GitHub_M
Published
Jun 11, 2026 at 17:13
Modified
Jun 11, 2026 at 18:20
Affected Product
Vendor
MariaDB
Product
server
Version
>= 10.6.1, < 10.6.27
Affected Versions
MariaDB server >= 10.6.1, < 10.6.27
MariaDB server >= 10.11.1, < 10.11.18
MariaDB server >= 11.4.1, < 11.4.12
MariaDB server >= 11.8.1, < 11.8.8
MariaDB server = 12.3.1
MariaDB server >= 10.11.1, < 10.11.18
MariaDB server >= 11.4.1, < 11.4.12
MariaDB server >= 11.8.1, < 11.8.8
MariaDB server = 12.3.1
CWE Classification
AI Assessment
AI Score
10 / 10
AI Severity
Critical
Vendor
MariaDB
Product
MariaDB Server
Version
10.6.1-10.6.26, 10.11.1-10.11.17, 11.4.1-11.4.11, 11.8.1-11.8.7, 12.3.1