CVE-2026-49261 (matched: mariadb)

  • Wednesday, 5th August, 2026
  • 16:06pm

A security flaw has been found in MariaDB, a popular open-source database software that many websites use to store content, user information, and other critical data. The issue impacts specific MariaDB versions: 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1, but only if the wsrep_notify_cmd setting is turned on. When this setting is enabled, an attacker who can add a new node to your MariaDB cluster with a specially crafted name could run unauthorized commands on your server, which could put your site and data at risk.

Fixes for this flaw are already available for all affected versions: 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. If you are not able to upgrade to these patched versions right away, you can disable the wsrep_notify_cmd setting as a temporary workaround to block the vulnerability.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-49261

« Back