CVE-2026-49261
Critical · CVSS 10.0MariaDB Server — OS Command Injection (CWE-78) via wsrep_notify_cmd joiner node name
- CVSS
- 10.0
- nvd
- EPSS
- 1.58%
- 73th pct
- KEV
- No
- Class
- oss containerizable
- CWE-78, CWE-78
Description
MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.
Search profile — drives PoC discovery
Symbols wsrep_notify_cmdjoiner nodewsrep_notifyMDEV-39721GHSA-3p3m-4x7c-p4pwwsrep_sstgalerawsrep_cluster_name
Keywords CVE-2026-49261MariaDB wsrep_notify_cmd command injectionMariaDB Galera OS command injectionMariaDB joiner node shell injectionMDEV-39721GHSA-3p3m-4x7c-p4pwMariaDB wsrep RCEMariaDB 10.6 10.11 11.4 11.8 wsrep exploit
Versions: 10.6.1–10.6.26, 10.11.1–10.11.17, 11.4.1–11.4.11, 11.8.1–11.8.7, 12.3.1
Affected packages
| Bitnami | mariadb | 10.11.1 → 10.11.18 |
| Bitnami | mariadb | 10.6.1 → 10.6.27 |
| Bitnami | mariadb | 11.4.1 → 11.4.12 |
| Bitnami | mariadb | 11.8.1 → 11.8.8 |
| Bitnami | mariadb | 12.3.1 → 12.3.2 |
| Bitnami | mariadb-min | 10.11.1 → 10.11.18 |
| Bitnami | mariadb-min | 10.6.1 → 10.6.27 |
| Bitnami | mariadb-min | 11.4.1 → 11.4.12 |
| Bitnami | mariadb-min | 11.8.1 → 11.8.8 |
| Bitnami | mariadb-min | 12.3.1 → 12.3.2 |
| Bitnami | mysql-client | 10.11.1 → 10.11.18 |
| Bitnami | mysql-client | 10.6.1 → 10.6.27 |
| Bitnami | mysql-client | 11.4.1 → 11.4.12 |
| Bitnami | mysql-client | 11.8.1 → 11.8.8 |
| Bitnami | mysql-client | 12.3.1 → 12.3.2 |
References
- https://github.com/MariaDB/server/security/advisories/GHSA-3p3m-4x7c-p4pw
- https://jira.mariadb.org/browse/MDEV-39721
- https://access.redhat.com/errata/RHSA-2026:25143
- https://access.redhat.com/errata/RHSA-2026:25145
- https://access.redhat.com/errata/RHSA-2026:33093
- https://access.redhat.com/errata/RHSA-2026:33412
- https://access.redhat.com/errata/RHSA-2026:33464
- https://access.redhat.com/errata/RHSA-2026:33481
- https://access.redhat.com/errata/RHSA-2026:33482
- https://access.redhat.com/errata/RHSA-2026:49522
- https://access.redhat.com/errata/RHSA-2026:52848
- https://access.redhat.com/errata/RHSA-2026:54142
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T18:30:14.000Z