Review reviewCritical

CVE-2026-49261

MariaDB server, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.

CVSS
9.8
EPSS
1.42%
70.1% percentile
CISA KEV
Not listed
Published
2026.06.12
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability1.42%
Technical severityCVSS 9.8

Vulnerability overview

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.

Affected product and versions

Product
MariaDB server, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8
Affected versions
>= >= 10.6.1, < 10.6.27, >= >= 10.11.1, < 10.11.18, >= >= 11.4.1, < 11.4.12, >= >= 11.8.1, < 11.8.8, >= = 12.3.1, >= 10.6.1 < 10.6.27, >= 10.11.1 < 10.11.18, >= 11.4.1 < 11.4.12, >= 11.8.1 < 11.8.8, 12.3.1
Fixed versions
10.6.27, 10.11.18, 11.4.12, 11.8.8

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that MariaDB server, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8 and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-78