CVE-2026-49261 (matched: mariadb)

  • Tuesday, 11th August, 2026
  • 22:05pm

A security vulnerability has been found in MariaDB, a widely used database software that many websites rely on to store user data, site content, and other important information. The flaw impacts specific MariaDB versions: 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1, but only if the `wsrep_notify_cmd` setting is turned on for your database configuration.

When this setting is enabled, an attacker could sneak harmful system commands into the name of a server that joins your database cluster. If this flaw is exploited, bad actors could gain unauthorized access to your website's stored data, alter or delete content, or run unwanted processes on your hosting account.

The team behind MariaDB has released updated software versions that fix this issue: 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. If you are unable to upgrade your MariaDB version right now, you can temporarily protect your site by disabling the `wsrep_notify_cmd` setting.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-49261

« Back