MariaDB has patched CVE-2026-49261, a critical OS command injection vulnerability that scores CVSS 10.0 and allows an unauthenticated remote attacker to execute arbitrary code on affected database servers. The vulnerability is in the wsrep_notify_cmd functionality, a component of Galera Cluster replication. Standalone MariaDB installations without Galera are not affected. Patches were released on May 27, 2026; the vulnerability was publicly disclosed on June 11, 2026.

This distinction matters before anything else. wsrep_notify_cmd is a configuration option specific to Galera Cluster, the synchronous multi-primary replication layer used in high-availability MariaDB deployments. It is not present or active in standard single-node MariaDB installations.

A deployment is vulnerable only if all three of the following are true:

MariaDB is running as part of a Galera Cluster
The wsrep_notify_cmd option is configured in the server settings (it has no value by default)
The server is running one of the affected versions

Bron: https://nvd.nist.gov/vuln/detail/CVE-2026-49261