Command Injection Affecting MariaDB/server package, versions [,10.6.27)[10.11.0, 10.11.18)[11.4.0, 11.4.12)[11.8.0,11.8.8)[12.3.1,12.3.2)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
1.51% (72nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-MARIADBSERVER-17426344
  • published23 Jun 2026
  • disclosed12 Jun 2026
  • creditLAKSHMIKANTHAN K

Introduced: 12 Jun 2026

CVE-2026-48165  (opens in a new tab)
CWE-78  (opens in a new tab)

How to fix?

Upgrade MariaDB/server to version 10.6.27, 10.11.18, 11.4.12, 11.8.8, 12.3.2 or higher.

Overview

Affected versions of this package are vulnerable to Command Injection via manipulation of the wsrep_sst_receive_address or wsrep_sst_donor global system variables. A user can execute arbitrary shell commands as the user ID of the mariadbd process on a galera joiner node by supplying crafted values to these variables.

Note This is only exploitable if the attacker has high-privileged access to the database instance.

CVSS Base Scores

version 4.0
version 3.1