← Back to browse · API

CVE-2026-49261

Severity
CRITICAL
CVSS
10.0
EPSS
0.01582
Risk score
40.55
CISA KEV
No
PoC
Yes
Published
2026-06-11
Modified
2026-08-12
First seen
2026-08-05
Aliases
EUVD-2026-36269
Products
Devolutions:Server 10.11.1, < 10.11.18, Devolutions:Server 10.6.1, < 10.6.27, Devolutions:Server 11.4.1, < 11.4.12, Devolutions:Server 11.8.1, < 11.8.8, Devolutions:Server = 12.3.1, linux, mariadb:mariadb, redhat, suse, ubuntu
Sources
nvd CVE-2026-49261
euvd EUVD-2026-36269
packetstorm 15bf204fa71fbd4429ebbd7d|CVE-2026-49261
packetstorm 7d22f04b7353e95949ca0680|CVE-2026-49261
packetstorm 0ea4bef64b3388424cbf9e35|CVE-2026-49261
packetstorm c14c16263502ea813333119a|CVE-2026-49261
packetstorm 254251df819cea3da01015cf|CVE-2026-49261
packetstorm 35095c9ffe80c2f592b5db71|CVE-2026-49261

Description

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.

References