CVE-2026-49261 (matched: mariadb)

  • Monday, 3rd August, 2026
  • 16:04pm

A security flaw has been identified in specific versions of MariaDB, a common open-source database tool many websites use to store content, user data, and other information. The issue only affects MariaDB versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1, and only if a setting called wsrep_notify_cmd is enabled on your server. If this setting is active, a bad actor could hide unauthorized commands inside the name of a database node connecting to your setup, which would let them run unwanted actions on your hosting environment. Patched versions of MariaDB that resolve this flaw are 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. If you cannot upgrade your MariaDB version right now, you can avoid the risk by turning off the wsrep_notify_cmd setting.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-49261

« Back