CVE-2026-44168

Published: May 26, 2026Last modified: June 3, 2026

Description

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not all parameters were properly validated which could allow a malicious joiner to execute arbitrary shell commands on the donor side via the mariabackup SST method. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.

Severity score breakdown

ParameterValue
Base score8
Attack VectorNETWORK
Attack complexityHIGH
Privileges requiredHIGH
User interactionNONE
ScopeCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSmariadbFixed (10.6.27-r0)
25 LTSmariadbFixed (11.4.11-r0)
StreammariadbFixed (11.8.7-r0)

References

ON THIS PAGE