Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-49261

Опубликовано: 11 июн. 2026
Источник: redhat
CVSS3: 9

Описание

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with wsrep_notify_cmd enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable wsrep_notify_cmd.

A flaw was found in MariaDB server. When the wsrep_notify_cmd feature is enabled, a remote attacker could exploit this vulnerability by embedding shell commands in the name of a joiner node. This could lead to arbitrary code execution on the server, allowing the attacker to take full control of the affected system.

Отчет

Red Hat has assessed this vulnerability as Important. Exploitation requires the wsrep_notify_cmd server variable to be explicitly set to a notification script by the administrator. This variable is empty by default in the upstream configuration, and Red Hat's shipped Galera configuration additionally defaults to wsrep_on=0. Additionally, the attacker must stand up a MariaDB/Galera node that is accepted into the cluster membership view in order to inject a malicious node name.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7mariadbNot affected
Red Hat Enterprise Linux 9mariadbNot affected
Red Hat Enterprise Linux 10mariadb10.11FixedRHSA-2026:3309329.06.2026
Red Hat Enterprise Linux 10mariadb11.8FixedRHSA-2026:3341230.06.2026
Red Hat Enterprise Linux 8mariadbFixedRHSA-2026:3346430.06.2026
Red Hat Enterprise Linux 9mariadbFixedRHSA-2026:3348130.06.2026
Red Hat Enterprise Linux 9mariadbFixedRHSA-2026:3348230.06.2026
Red Hat Hardened Imagesmariadb11-8-main-11.8.8-1.hum1FixedRHSA-2026:2514310.06.2026
Red Hat Hardened Imagesmariadb10-11-main-10.11.18-1.hum1FixedRHSA-2026:2514510.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2487957mariadb: MariaDB Server: Arbitrary code execution via wsrep_notify_cmd

9 Critical

CVSS3

Связанные уязвимости

CVSS3: 10
ubuntu
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.

CVSS3: 10
nvd
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.

CVSS3: 10
debian
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. Versions ...

CVSS3: 10
github
около 2 месяцев назад

unsafe parameter handing in `wsrep_notify_cmd`

oracle-oval
29 дней назад

ELSA-2026-33482: mariadb:10.11 security, bug fix, and enhancement update (IMPORTANT)

9 Critical

CVSS3