CVE-2021-27928 is a remote code execution vulnerability in MariaDB (10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, 10.5 before 10.5.9), Percona Server (through 2021-03-03), and the wsrep patch (through 2021-03-03) for MySQL. The vulnerability arises from an untrusted search path, allowing a database SUPER user to inject and execute arbitrary OS commands by modifying the wsrep_provider and wsrep_notify_cmd variables, leading to eval injection. This issue does not affect Oracle MySQL products.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository provides a proof-of-concept (PoC) exploit for CVE-2021-27928, a vulnerability in MariaDB (and related MySQL/Percona versions) that allows a database user with SUPER privileges to execute arbitrary code via the wsrep_provider system variable. The repository contains a Dockerfile to build a vulnerable MariaDB 10.4.12 container, a docker-compose.yaml to configure the container's network and environment, and a supervisord.conf to run both MariaDB and SSH services. The README.md details the exploitation process: an attacker generates a malicious .so file (reverse shell payload) using msfvenom, uploads it to the container via SSH, and sets the wsrep_provider variable to the payload's path using the mysql client. This results in the MariaDB process loading the attacker's .so file and executing the reverse shell, granting the attacker a shell as the 'mysql' user. The exploit requires specific configuration (writable /usr/lib/galera, SSH access, and vulnerable MariaDB version) and is intended for demonstration in a controlled environment. The main attack vector is network-based, leveraging SSH and MySQL connections. Notable endpoints include the container's IP (192.168.128.5), the attacker's IP (192.168.128.1), and file paths for the payload. The repository is structured as a PoC environment for demonstrating the vulnerability, not as a weaponized or automated exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.