Executive brief
MariaDB is a widely used database server for storing and managing corporate data. A security flaw in its Galera Cluster component allows a high-privileged database user to execute unauthorized operating system commands on the server. This could lead to a full system takeover, data theft, or disruption of database services.
Technical details
An OS command injection vulnerability (CWE-78) exists in MariaDB Server's Galera Cluster implementation. The root cause is the improper neutralization of special elements within the 'wsrep_sst_receive_address' and 'wsrep_sst_donor' global system variables. A remote attacker with high privileges (such as SUPER privileges) can modify these variables at runtime to inject and execute shell commands with the privileges of the 'mariadbd' process on a joiner node. The attack requires network access to the database and high-level authentication. Patches are available in versions 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2.
Affected products
- MariaDB MariaDB Server 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, 12.3.1
Timeline
- 2026-05-20: disclosed: Issue reported and resolved in internal tracker
- 2026-06-12: advisory: CVE published and NVD entry created