A security flaw has been identified in MariaDB, a widely used open-source database tool that many websites rely on to store content, user data, and other critical site information. The issue affects specific MariaDB versions (10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1) if the `wsrep_notify_cmd` setting is enabled. When this setting is active, attackers can embed malicious shell commands in the name of a node that joins your database cluster, and these commands will run automatically on your server without additional approval.
This vulnerability creates risk because unauthorized commands running on your server could allow bad actors to access your private website data, alter your site's content, or gain control
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-49261