MariaDB disclosed CVE-2026-49261, a command execution vulnerability in MariaDB Server tied to unsafe parameter handling in wsrep_notify_cmd. When that feature is enabled, shell commands embedded in the name of a joiner node can be executed by the server, creating a risk in Galera-based cluster environments where peer-supplied fields are substituted into shell commands without proper sanitization. The issue is also tracked as GHSA-3p3m-4x7c-p4pw and MariaDB internal ticket MDEV-39721.
The vulnerability affects MariaDB versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1. MariaDB released fixes in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2, and advised organizations that cannot patch immediately to disable wsrep_notify_cmd. The flaw was reported by letchu_pkt.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
A CVE entry for CVE-2026-49261 described the MariaDB server vulnerability affecting multiple release branches when wsrep_notify_cmd is enabled, allowing execution of shell commands embedded in a joiner node name. The entry reiterated the fixed versions and the mitigation of disabling wsrep_notify_cmd.
MariaDB made fixes available in versions 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2 for the wsrep_notify_cmd command execution issue. MariaDB also recommended disabling wsrep_notify_cmd as a mitigation for users unable to upgrade immediately.
A GitHub Security Advisory disclosed a MariaDB Server vulnerability, GHSA-3p3m-4x7c-p4pw, in which shell commands embedded in a joiner node name could be executed when wsrep_notify_cmd is enabled. The advisory credited letchu_pkt for reporting the issue and listed affected MariaDB versions.
MariaDB published Jira issue MDEV-39721 concerning unsafe handling in wsrep_notify_cmd, documenting the need to sanitize peer-supplied fields before shell substitution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcejira.mariadb.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.