MariaDB Server Vulnerabilities Allow CVSS 10 Attacks
ID: d9cd915c-2b32-5701-ad47-23488596b5b1
STIX ID: report--d9cd915c-2b32-5701-ad47-23488596b5b1
Feed Name: securityonline.info
Threat Score
Three serious MariaDB Server vulnerabilities (CVE-2026-48163, CVE-2026-48165, CVE-2026-49261) enable arbitrary shell command execution during Galera cluster State Transfer (SST) and via the `wsrep_notify_cmd` setting; administrators are advised to update immediately to 10.6.27, 10.11.18, 11.4.12, 11.8.8, or 12.3.2 or apply mitigations (disable `wsrep_notify_cmd`, remove `wsrep_sst_rsync`) — no confirmed exploitation reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
