Junglewise Threat Intelligence

CVE-2026-48165: MariaDB Server OS command injection in Galera Cluster variables

CVE-2026-48165 · Severity: high · CVSS 8 · Published 2026-06-12

Vendors: Mariadb.

Executive brief

MariaDB is a widely used database server for storing and managing corporate data. A security flaw in its Galera Cluster component allows a high-privileged database user to execute unauthorized operating system commands on the server. This could lead to a full system takeover, data theft, or disruption of database services.

Technical details

An OS command injection vulnerability (CWE-78) exists in MariaDB Server's Galera Cluster implementation. The root cause is the improper neutralization of special elements within the 'wsrep_sst_receive_address' and 'wsrep_sst_donor' global system variables. A remote attacker with high privileges (such as SUPER privileges) can modify these variables at runtime to inject and execute shell commands with the privileges of the 'mariadbd' process on a joiner node. The attack requires network access to the database and high-level authentication. Patches are available in versions 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2.

Affected products

  • MariaDB MariaDB Server 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, 12.3.1

Timeline

  • 2026-05-20: disclosed: Issue reported and resolved in internal tracker
  • 2026-06-12: advisory: CVE published and NVD entry created

References