CVE-2026-48163: MariaDB: wsrep SST unsafe parameter handling on the donor side (rsync)
Last updated 11 July 2026
Other sources
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not all parameters were properly validated which could allow a malicious joiner to execute arbitrary shell commands on the donor side via the rsync SST method. This issue has been patched in versions 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/mariadbto a version that resolves this vulnerability.Fixed in 1:10.11.18-0+deb12u1Fixed in 1:11.8.8-1 - Upgrade
Upgrade
MariaDB server (wsrep SST via rsync)to a version that resolves this vulnerability.Fixed in 10.6.27 - Upgrade
Upgrade
MariaDB server (wsrep SST via rsync)to a version that resolves this vulnerability.Fixed in 10.11.18 - Upgrade
Upgrade
MariaDB server (wsrep SST via rsync)to a version that resolves this vulnerability.Fixed in 11.4.12 - Upgrade
Upgrade
MariaDB server (wsrep SST via rsync)to a version that resolves this vulnerability.Fixed in 11.8.8 - Upgrade
Upgrade
MariaDB server (wsrep SST via rsync)to a version that resolves this vulnerability.Fixed in 12.3.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48163?
CVE-2026-48163 has a severity rating of high (8).
How do I fix CVE-2026-48163?
To resolve CVE-2026-48163, upgrade to MariaDB versions 10.6.27, 10.11.18, 11.4.12, 11.8.8, or 12.3.1 or later.
What is the risk associated with CVE-2026-48163?
CVE-2026-48163 has a risk score of 65, indicating a significant potential impact.
What kind of vulnerability is CVE-2026-48163?
CVE-2026-48163 is categorized as an OS Command Injection vulnerability.
Which versions of MariaDB are affected by CVE-2026-48163?
CVE-2026-48163 affects MariaDB versions from 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1.