CVE-2026-49261 (matched: mariadb)

  • Saturday, 15th August, 2026
  • 10:06am

A security vulnerability has been found in MariaDB, a common database software used by many websites to store site data. This flaw only affects specific MariaDB versions (10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1) if the wsrep_notify_cmd setting is turned on. If your site uses an affected setup, an attacker who can connect to your database cluster as a new node could run unauthorized system commands on your server by embedding those commands in the name they use for their connection.

Fixed versions of MariaDB that resolve this issue are now available: 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. If you cannot upgrade to one of these fixed versions right now, you can avoid the risk by disabling the wsrep_notify_cmd setting.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-49261

« Back