Command Injection Risk in MariaDB Server Affects Versions Across Multiple Releases
CVE-2026-48163

8HIGH

Key Information:

Vendor

Mariadb

Status
Vendor
CVE Published:
12 June 2026

What is CVE-2026-48163?

A command injection vulnerability exists in MariaDB server that affects several versions. During the State Snapshot Transfer (SST), an insufficient validation of parameters from a joining node can result in the execution of arbitrary shell commands on the donor side. This risk emerges specifically when utilizing the rsync SST method, presenting a significant threat that malicious entities could exploit to execute unauthorized commands. Versions 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2 contain patches that address this issue, significantly enhancing the security posture of affected installations.

Affected Version(s)

server >= 10.6.1, < 10.6.27 < 10.6.1, 10.6.27

server >= 10.11.1, < 10.11.18 < 10.11.1, 10.11.18

server >= 11.4.1, < 11.4.12 < 11.4.1, 11.4.12

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.