CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-49261

Critical · CVSS 10.0

MariaDB Server — OS Command Injection (CWE-78) via wsrep_notify_cmd joiner node name

CVSS
10.0
nvd
EPSS
1.58%
73th pct
KEV
No
Class
oss containerizable
CWE-78, CWE-78

Description

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.

Search profile — drives PoC discovery

Symbols wsrep_notify_cmdjoiner nodewsrep_notifyMDEV-39721GHSA-3p3m-4x7c-p4pwwsrep_sstgalerawsrep_cluster_name
Keywords CVE-2026-49261MariaDB wsrep_notify_cmd command injectionMariaDB Galera OS command injectionMariaDB joiner node shell injectionMDEV-39721GHSA-3p3m-4x7c-p4pwMariaDB wsrep RCEMariaDB 10.6 10.11 11.4 11.8 wsrep exploit
Versions: 10.6.1–10.6.26, 10.11.1–10.11.17, 11.4.1–11.4.11, 11.8.1–11.8.7, 12.3.1

Affected packages

Bitnami mariadb 10.11.1 → 10.11.18
Bitnami mariadb 10.6.1 → 10.6.27
Bitnami mariadb 11.4.1 → 11.4.12
Bitnami mariadb 11.8.1 → 11.8.8
Bitnami mariadb 12.3.1 → 12.3.2
Bitnami mariadb-min 10.11.1 → 10.11.18
Bitnami mariadb-min 10.6.1 → 10.6.27
Bitnami mariadb-min 11.4.1 → 11.4.12
Bitnami mariadb-min 11.8.1 → 11.8.8
Bitnami mariadb-min 12.3.1 → 12.3.2
Bitnami mysql-client 10.11.1 → 10.11.18
Bitnami mysql-client 10.6.1 → 10.6.27
Bitnami mysql-client 11.4.1 → 11.4.12
Bitnami mysql-client 11.8.1 → 11.8.8
Bitnami mysql-client 12.3.1 → 12.3.2

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T18:30:14.000Z