CVE-2026-48163
MariaDB Server Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-48163 is an OS command injection vulnerability in MariaDB Community Server affecting the wsrep State Snapshot Transfer (SST) mechanism via the rsync method. During SST, the donor node interpolates parameters received from the joiner node into shell command lines without sufficient validation, allowing a malicious joiner to execute arbitrary shell commands on the donor. Affected versions include 10.6.1–10.6.26, 10.11.1–10.11.17, 11.4.1–11.4.11, 11.8.1–11.8.7, and 12.3.1. The vulnerability was published on June 12, 2026, with the GitHub Security Advisory (GHSA-rpgv-q6gv-684r) first published June 2, 2026. It carries a CVSS v3.1 base score of 8.0 (High) per the GitHub advisory, or 7.2 (High) per NVD (GitHub Advisory, Feedly).

Détails techniques

The root cause is CWE-78 (Improper Neutralization of Special Elements used in an OS Command), specifically within the wsrep_sst_rsync script used during Galera cluster State Snapshot Transfer operations (GitHub Advisory). When a joiner node initiates an SST, it sends parameters to the donor node; the donor's wsrep_sst_rsync script interpolates these parameters directly into shell command lines without fully sanitizing them, enabling argument/command injection. Exploitation requires the attacker to control a joiner node within the cluster (high privileges required) and network access to the donor, but no user interaction is needed. The issue is tracked upstream as MDEV-39648 (GitHub Advisory).

Impact

A malicious joiner node can execute arbitrary shell commands on the donor node with the privileges of the MariaDB/wsrep process, resulting in full compromise of confidentiality, integrity, and availability on the donor host. This could allow an attacker to exfiltrate database contents, modify or destroy data, install backdoors, or pivot to other systems accessible from the donor node. The scope is marked as "Changed" in the GitHub advisory CVSS vector, indicating that the impact can extend beyond the vulnerable MariaDB component itself (GitHub Advisory, Feedly).

Exploitabilité

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.698%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high privileges (control of a joiner node in the Galera cluster), which limits the attack surface to insider threats or scenarios where an attacker has already compromised a cluster member (GitHub Advisory).

Étapes d’exploitation

  1. Reconnaissance: Identify a target MariaDB Galera cluster running a vulnerable version (10.6.1–10.6.26, 10.11.1–10.11.17, 11.4.1–11.4.11, 11.8.1–11.8.7, or 12.3.1) with the rsync SST method enabled.
  2. Gain joiner node access: Obtain control of a node that can join the cluster, either by compromising an existing cluster member or by introducing a rogue node with valid cluster credentials.
  3. Initiate SST: Trigger a State Snapshot Transfer from the malicious joiner node to the donor node, which causes the donor to execute the wsrep_sst_rsync script.
  4. Inject malicious parameters: Craft SST parameters sent from the joiner that include shell metacharacters or command separators (e.g., ;, $(...), |) in fields that are interpolated unsanitized into the donor's shell command line.
  5. Achieve arbitrary command execution: The donor's wsrep_sst_rsync script executes the injected shell commands with the privileges of the MariaDB process, enabling reverse shell establishment, data exfiltration, or further lateral movement (GitHub Advisory, Feedly).

Indicateurs de compromis

  • Logs: Unexpected or malformed entries in MariaDB error logs (/var/log/mysql/error.log) during SST operations; shell error messages or unusual command output appearing in wsrep/SST log files.
  • Process: Unusual child processes spawned by the MariaDB or wsrep_sst_rsync process (e.g., /bin/bash, curl, wget, nc, python) during or after an SST event; unexpected network connections initiated from the donor node.
  • Network: Outbound connections from the donor node to unknown external IPs immediately following an SST operation; unexpected rsync traffic with anomalous parameters.
  • File System: New or modified files in the MariaDB data directory or system directories created during SST; presence of web shells, cron jobs, or SSH authorized_keys modifications made by the MariaDB process account.

Atténuation et solutions de contournement

Upgrade MariaDB to the patched versions: 10.6.27, 10.11.18, 11.4.12, 11.8.8, or 12.3.2 (GitHub Advisory, MariaDB Releases). As a temporary workaround, remove the wsrep_sst_rsync script from donor hosts to prevent the rsync SST method from being used; an alternative SST method (e.g., mariabackup) should be configured if SST is required. Additionally, restrict cluster membership to trusted nodes only and enforce network-level controls to limit which hosts can initiate SST operations.

Réactions de la communauté

The vulnerability received coverage from security news outlets including SecurityOnline.info and BeyondMachines, which highlighted it as a notable MariaDB command injection flaw (SecurityOnline). SUSE issued security updates (SUSE-SU-2026:2282-1, SUSE-SU-2026:2330-1) and openSUSE published corresponding advisories, reflecting prompt downstream patching activity (SUSE Advisory). The Singapore Cyber Security Agency (CSA) also issued an alert (AL-2026-078) referencing this vulnerability. Community discussion on Mastodon and Bluesky noted the issue but overall sentiment reflected low immediate risk given the high privilege requirement and absence of public exploits.

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté MariaDB Server Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-55215HIGH7.5
  • MariaDB Server logoMariaDB Server
  • cpe:2.3:a:mariadb:mariadb
NonOuiAug 28, 2026
CVE-2026-48165HIGH7.2
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-client-utils
NonOuiJun 12, 2026
CVE-2026-48163HIGH7.2
  • MariaDB Server logoMariaDB Server
  • mariadb-rocksdb-engine-debuginfo
NonOuiJun 12, 2026
CVE-2026-55855MEDIUM6.5
  • MariaDB Server logoMariaDB Server
  • cpe:2.3:a:mariadb:mariadb
NonOuiAug 28, 2026
CVE-2026-55854MEDIUM5.9
  • MariaDB Server logoMariaDB Server
  • cpe:2.3:a:mariadb:mariadb
NonOuiAug 28, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités