Critical Alert 1 Active Exploit Detected Today

CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2026-48165NVD

Vulnerability Summary

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, a high-privileged MariaDB user could've used wsrep_sst_receive_address or wsrep_sst_donor global system variables to execute shell commands as the uid of the mariadbd process on the galera joiner node. This issue has been patched in versions 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2.
Severity Level
HIGH(8.0)
Published Date
Jun 12, 2026
Last Modified
Aug 3, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
1.51%Probability
Root Weakness (CWE)
The software constructs all or part of an OS command using externally-influenced input, but does not properly neutralize special elements.
CVSS v3.1 Base Metrics — Score 8.0 (HIGH)
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredHigh
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

Affected & Patched Versions

Affected Versions
  • Mariadb Mariadb >= 10.6.1 and < 10.6.27
  • Mariadb Mariadb >= 10.11.1 and < 10.11.18
  • Mariadb Mariadb >= 11.4.1 and < 11.4.12
  • Mariadb Mariadb >= 11.8.1 and < 11.8.8
  • Mariadb Mariadb
Patched Versions
  • Mariadb Mariadb 10.6.27
  • Mariadb Mariadb 10.11.18
  • Mariadb Mariadb 11.4.12
  • Mariadb Mariadb 11.8.8
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.