CVE-2026-49261
MariaDB servers from versions 10.6.1 to 12.3.1 with wsrep_notify_cmd enabled can run arbitrary shell commands when a node joins a cluster. This allows an attacker to execute commands with the privileges of the MariaDB process. The vulnerability is critical because it requires no authentication and can compromise the entire system.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
MariaDB community server versions 10.6.1–10.6.26, 10.11.1–10.11.17, 11.4.1–11.4.11, 11.8.1–11.8.7, and 12.3.1 when wsrep_notify_cmd is enabled.
Real-world impact
An attacker could run any shell command on the host, potentially taking full control of the server.
Why this severity
The CVSS score of 10 reflects that the flaw allows remote attackers to execute arbitrary code without authentication, with complete control over confidentiality, integrity, and availability.
What to do about it
- 01Upgrade MariaDB to a fixed version (10.6.27, 10.11.18, 11.4.12, 11.8.8, or 12.3.2 or later).
NVD-referenced vendor advisory
Timeline
- Jun 11, 2026 · Jun 11, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Aug 3, 2026 · 14h agoAdvisory updatedThe NVD record was last revised.
- Aug 3, 2026 · 13h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/MariaDB/server/security/adv…vendor advisory
- jira.mariadb.org/browse/MDEV-39721issue tracking
- access.redhat.com/errata/RHSA-2026:25143
- access.redhat.com/errata/RHSA-2026:25145
- access.redhat.com/errata/RHSA-2026:33093
- access.redhat.com/errata/RHSA-2026:33412
- access.redhat.com/errata/RHSA-2026:33464
- access.redhat.com/errata/RHSA-2026:33481
- access.redhat.com/errata/RHSA-2026:33482
- access.redhat.com/errata/RHSA-2026:49522
- access.redhat.com/security/cve/CVE-2026-49261
- bugzilla.redhat.com/show_bug.cgi
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2…