Command Injection Vulnerability in MariaDB Server Affects Multiple Versions
CVE-2026-44168
8HIGH
What is CVE-2026-44168?
A command injection vulnerability exists in the MariaDB server due to insufficient validation of parameters sent from the joiner node during the State Snapshot Transfer (SST). This flaw enables a potentially malicious joiner to craft specific commands that could be executed on the donor node, risking the integrity and security of the environment. Patches have been released in newer versions to mitigate this risk.
Affected Version(s)
server >= 10.6.1, < 10.6.26 < 10.6.1, 10.6.26
server >= 10.11.1, < 10.11.17 < 10.11.1, 10.11.17
server >= 11.4.1, < 11.4.11 < 11.4.1, 11.4.11
