Command Injection Risk in MariaDB Server Affects Versions Across Multiple Releases
CVE-2026-48163
What is CVE-2026-48163?
A command injection vulnerability exists in MariaDB server that affects several versions. During the State Snapshot Transfer (SST), an insufficient validation of parameters from a joining node can result in the execution of arbitrary shell commands on the donor side. This risk emerges specifically when utilizing the rsync SST method, presenting a significant threat that malicious entities could exploit to execute unauthorized commands. Versions 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2 contain patches that address this issue, significantly enhancing the security posture of affected installations.
Affected Version(s)
server >= 10.6.1, < 10.6.27 < 10.6.1, 10.6.27
server >= 10.11.1, < 10.11.18 < 10.11.1, 10.11.18
server >= 11.4.1, < 11.4.12 < 11.4.1, 11.4.12
