Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-49261

Опубликовано: 11 июн. 2026
Источник: redhat
CVSS3: 9
EPSS Низкий

Описание

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with wsrep_notify_cmd enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable wsrep_notify_cmd.

A flaw was found in MariaDB server. When the wsrep_notify_cmd feature is enabled, a remote attacker could exploit this vulnerability by embedding shell commands in the name of a joiner node. This could lead to arbitrary code execution on the server, allowing the attacker to take full control of the affected system.

Отчет

Red Hat has assessed this vulnerability as Important. Exploitation requires the wsrep_notify_cmd server variable to be explicitly set to a notification script by the administrator. This variable is empty by default in the upstream configuration, and Red Hat's shipped Galera configuration additionally defaults to wsrep_on=0. Additionally, the attacker must stand up a MariaDB/Galera node that is accepted into the cluster membership view in order to inject a malicious node name.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7mariadbNot affected
Red Hat Enterprise Linux 9mariadbNot affected
Red Hat Enterprise Linux 10mariadb10.11FixedRHSA-2026:3309329.06.2026
Red Hat Enterprise Linux 10mariadb11.8FixedRHSA-2026:3341230.06.2026
Red Hat Enterprise Linux 10.0 Extended Update Supportmariadb10.11FixedRHSA-2026:4952203.08.2026
Red Hat Enterprise Linux 8mariadbFixedRHSA-2026:3346430.06.2026
Red Hat Enterprise Linux 9mariadbFixedRHSA-2026:3348130.06.2026
Red Hat Enterprise Linux 9mariadbFixedRHSA-2026:3348230.06.2026
Red Hat Enterprise Linux 9.4 Update Services for SAP SolutionsmariadbFixedRHSA-2026:5284810.08.2026
Red Hat Enterprise Linux 9.6 Extended Update SupportmariadbFixedRHSA-2026:5414212.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2487957mariadb: MariaDB Server: Arbitrary code execution via wsrep_notify_cmd

EPSS

Процентиль: 74%
0.01582
Низкий

9 Critical

CVSS3

Связанные уязвимости

CVSS3: 10
ubuntu
3 месяца назад

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.

CVSS3: 10
nvd
3 месяца назад

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.

CVSS3: 10
debian
3 месяца назад

MariaDB server is a community developed fork of MySQL server. Versions ...

CVSS3: 9.8
redos
около 1 месяца назад

Уязвимость mariadb11.8

CVSS3: 9.8
redos
около 1 месяца назад

Уязвимость mariadb11.4

EPSS

Процентиль: 74%
0.01582
Низкий

9 Critical

CVSS3