Remote Code Execution Vulnerability in MariaDB Server by MariaDB Foundation
CVE-2026-48165
8HIGH
What is CVE-2026-48165?
A high-privileged user in MariaDB server may exploit the 'wsrep_sst_receive_address' or 'wsrep_sst_donor' global system variables to execute arbitrary shell commands under the uid of the mariadbd process on a Galera joiner node. This vulnerability affects various versions of MariaDB and has been addressed in subsequent updates to ensure system integrity and security.
Affected Version(s)
server >= 10.6.1, < 10.6.27 < 10.6.1, 10.6.27
server >= 10.11.1, < 10.11.18 < 10.11.1, 10.11.18
server >= 11.4.1, < 11.4.12 < 11.4.1, 11.4.12
