MariaDB Server <10.6.27, <10.11.18 Exec via wsrep_notify_cmd
CVE-2026-49261 Published on June 11, 2026
MariaDB server has unsafe parameter handling in `wsrep_notify_cmd`
MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.
Vulnerability Analysis
CVE-2026-49261 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Weakness Type
What is a Shell injection Vulnerability?
The software constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVE-2026-49261 has been classified to as a Shell injection vulnerability or weakness.
Products Associated with CVE-2026-49261
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-49261 are published in these products:
Affected Versions
MariaDB server:- Version >= 10.6.1, < 10.6.27 is affected.
- Version >= 10.11.1, < 10.11.18 is affected.
- Version >= 11.4.1, < 11.4.12 is affected.
- Version >= 11.8.1, < 11.8.8 is affected.
- Version = 12.3.1 is affected.
- Version 3:10.11.18-1.el10_2 and below * is unaffected.
- Version 3:11.8.8-1.el10_2 and below * is unaffected.
- Version 8100020260616102001.489197e6 and below * is unaffected.
- Version 9080020260612104015.rhel9 and below * is unaffected.
- Version 9080020260612103452.rhel9 and below * is unaffected.
- Version 11.8.8-1.hum1 and below * is unaffected.
- Version 10.11.18-1.hum1 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.