CVE-2026-47847: Medium severity Bitnami MariaDB Galera (container image) vulnerability

Published Jun 18, 2026
·
Updated

Bitnami MariaDB Galera container images and Helm chart are affected by a hardcoded default credential vulnerability in the Galera replication health-check user. The MARIADBREPLICATIONUSER and MARIADBREPLICATIONPASSWORD environment variables defaulted to monitor and monitor respectively. This user is granted REPLICATION CLIENT privileges from any host ('%'). The Bitnami Helm chart for MariaDB Galera did not expose parameters to configure this user's credentials, resulting in all chart deployments using this publicly known credential by default.

Affected versions — Container image: 10.6.x prior to 10.6.27-photon-5-r0; 10.11.x prior to 10.11.17-photon-5-r1; 11.4.x prior to 11.4.12-photon-5-r0; 11.8.x prior to 11.8.7-photon-5-r1; 12.3.x prior to 12.3.2-photon-5-r0 / 12.3.2-debian-12-r0. Helm chart: prior to 18.3.0.

Affected Software

2 affected components
Bitnami MariaDB Galera (container image)<10.6.27-photon-5-r0, <10.11.17-photon-5-r1, <11.4.12-photon-5-r0, <11.8.7-photon-5-r1, <12.3.2-photon-5-r0, <12.3.2-debian-12-r0
Bitnami MariaDB Galera Helm chart<18.3.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Bitnami MariaDB Galera container image to a version that resolves this vulnerability.

    Fixed in 10.6.27-photon-5-r0
  2. Upgrade

    Upgrade Bitnami MariaDB Galera container image to a version that resolves this vulnerability.

    Fixed in 10.11.17-photon-5-r1
  3. Upgrade

    Upgrade Bitnami MariaDB Galera container image to a version that resolves this vulnerability.

    Fixed in 11.4.12-photon-5-r0
  4. Upgrade

    Upgrade Bitnami MariaDB Galera container image to a version that resolves this vulnerability.

    Fixed in 11.8.7-photon-5-r1
  5. Upgrade

    Upgrade Bitnami MariaDB Galera container image to a version that resolves this vulnerability.

    Fixed in 12.3.2-photon-5-r0
  6. Upgrade

    Upgrade Bitnami MariaDB Galera container image to a version that resolves this vulnerability.

    Fixed in 12.3.2-debian-12-r0
  7. Upgrade

    Upgrade Bitnami MariaDB Galera Helm chart to a version that resolves this vulnerability.

    Fixed in 18.3.0
  8. Configuration

    In Helm values.yaml or container environment variables, set MARIADB_REPLICATION_USER to a non-default username (not 'monitor') and set MARIADB_REPLICATION_PASSWORD to a strong unique password. Do not rely on the default values 'monitor'/'monitor'.

    Bitnami MariaDB Galera (Helm chart values or container environment) MARIADB_REPLICATION_USER / MARIADB_REPLICATION_PASSWORD = MARIADB_REPLICATION_USER must not equal 'monitor'; MARIADB_REPLICATION_PASSWORD must not equal 'monitor' (use a strong, unique password)
  9. Compensating control

    Restrict access for the replication user granted from any host ('%'): change the user host restriction and/or network controls so REPLICATION CLIENT privileges are only usable from specific replica hostnames/IPs or internal network ranges. Apply firewall/ACL rules to limit connections to the MariaDB Galera ports to trusted hosts.

  10. Operational

    Rotate existing deployments' replication credentials: update the deployment Helm values or container secrets, change the database account password (for example: ALTER USER 'monitor'@'%' IDENTIFIED BY '<new_password>'; or create a new replication user and remove the default), apply the updated secrets, and restart/redeploy pods so the new credentials take effect.

Event History

Jun 18, 2026
CVE Published
via MITRE·06:37 PM
Data Sourced
via MITRE·06:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-47847?

The severity of CVE-2026-47847 is medium, rated at 5.3.

2

How do I fix CVE-2026-47847?

To fix CVE-2026-47847, change the default MARIADB_REPLICATION_USER and MARIADB_REPLICATION_PASSWORD environment variables from their default values.

3

What products are affected by CVE-2026-47847?

CVE-2026-47847 affects Bitnami MariaDB Galera container images and the corresponding Helm chart.

4

What exploit type is associated with CVE-2026-47847?

CVE-2026-47847 is associated with unauthorized access due to hardcoded default credentials.

5

Is CVE-2026-47847 a critical vulnerability?

CVE-2026-47847 is not considered critical but poses a security risk due to potential unauthorized access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203