Command Injection Affecting MariaDB/server package, versions [,10.6.27)[10.11.0, 10.11.18)[11.4.0, 11.4.12)[11.8.0, 11.8.8)[12.3.1,12.3.2)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
1.58% (74th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-MARIADBSERVER-17426372
  • published23 Jun 2026
  • disclosed11 Jun 2026
  • creditLAKSHMIKANTHAN K

Introduced: 11 Jun 2026

CVE-2026-49261  (opens in a new tab)
CWE-78  (opens in a new tab)

How to fix?

Upgrade MariaDB/server to version 10.6.27, 10.11.18, 11.4.12, 11.8.8, 12.3.2 or higher.

Overview

Affected versions of this package are vulnerable to Command Injection via the wsrep_notify_cmd variable. An attacker can execute arbitrary shell commands on the server by embedding malicious commands in the name of a joiner node that is accepted into the cluster membership view.

Note: This is only exploitable if the wsrep_notify_cmd server variable is explicitly set to a notification script and the attacker is able to join the Galera cluster as a node.

Workaround

This vulnerability can be mitigated by unsetting the wsrep_notify_cmd variable or removing the notification script, and by restricting network access to Galera replication ports (4567, 4568, 4444) to trusted cluster nodes only.

CVSS Base Scores

version 4.0
version 3.1