CVE-2026-44168: MariaDB: wsrep SST unsafe parameter handling on the donor side
Last updated 11 July 2026
Other sources
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not all parameters were properly validated which could allow a malicious joiner to execute arbitrary shell commands on the donor side via the mariabackup SST method. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/mariadbto a version that resolves this vulnerability.Fixed in 1:10.11.18-0+deb12u1Fixed in 1:11.8.8-1 - Upgrade
Upgrade
MariaDB server (wsrep SST unsafe parameter handling on the donor side)to a version that resolves this vulnerability.Fixed in 10.6.26 - Upgrade
Upgrade
MariaDB server (wsrep SST unsafe parameter handling on the donor side)to a version that resolves this vulnerability.Fixed in 10.11.17 - Upgrade
Upgrade
MariaDB server (wsrep SST unsafe parameter handling on the donor side)to a version that resolves this vulnerability.Fixed in 11.4.11 - Upgrade
Upgrade
MariaDB server (wsrep SST unsafe parameter handling on the donor side)to a version that resolves this vulnerability.Fixed in 11.8.7 - Upgrade
Upgrade
MariaDB server (wsrep SST unsafe parameter handling on the donor side)to a version that resolves this vulnerability.Fixed in 12.3.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44168?
CVE-2026-44168 has a severity rating of high with a score of 8.
How do I fix CVE-2026-44168?
To fix CVE-2026-44168, upgrade to MariaDB versions 10.6.26 or later, 10.11.17 or later, 11.4.11 or later, 11.8.7 or later, or 12.3.1.
What impact does CVE-2026-44168 have on MariaDB?
CVE-2026-44168 can lead to OS command injection due to unsafe parameter handling during the state transfer (SST) process.
Which versions of MariaDB are affected by CVE-2026-44168?
CVE-2026-44168 affects MariaDB versions from 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1.
What is the mitigation for CVE-2026-44168?
Mitigation for CVE-2026-44168 involves applying the appropriate updates to the affected MariaDB versions as mentioned in the fix.