CVE-2026-49261 (matched: mariadb)

  • Tuesday, 11th August, 2026
  • 16:04pm

A security flaw has been identified in MariaDB, the popular open-source database software many websites use to store user and site data. The issue affects specific versions of MariaDB (10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1) if the `wsrep_notify_cmd` setting is enabled. When this setting is active, attackers can run unauthorized commands on your server by using a specially crafted name for a node joining your MariaDB cluster.

This vulnerability has been resolved in updated MariaDB versions: 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. If you are unable to upgrade your MariaDB version right now, you can disable the `wsrep_notify_cmd` setting as a temporary workaround to eliminate the risk.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-49261

« Back