logo

MariaDB Server Vulnerabilities Allow CVSS 10 Attacks

ID: d9cd915c-2b32-5701-ad47-23488596b5b1

STIX ID: report--d9cd915c-2b32-5701-ad47-23488596b5b1

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-06-23

Date Updated: 2026-06-23

Author: Do Son

...
...

Three serious MariaDB Server vulnerabilities (CVE-2026-48163, CVE-2026-48165, CVE-2026-49261) enable arbitrary shell command execution during Galera cluster State Transfer (SST) and via the `wsrep_notify_cmd` setting; administrators are advised to update immediately to 10.6.27, 10.11.18, 11.4.12, 11.8.8, or 12.3.2 or apply mitigations (disable `wsrep_notify_cmd`, remove `wsrep_sst_rsync`) — no confirmed exploitation reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.