Back to search

MariaDB

MariaDB

See the latest tracked release, confirm when it was published, and subscribe for update emails.

Current version
Last checked: 2026-06-16

10.6.27

Release date
May 27, 2026
Security status
8 high-severity CVEs tracked in the last 90 days. Current version not affected.

Source

endoflife.date

Public release notes are linked for the latest stored release.

Release history

See the latest published releases stored for this product.

Version Published Notes
10.6.27 2026-05-27 Release Notes
10.6.26 2026-05-14 Release Notes
10.6.25 2026-02-04 Release Notes

Vulnerability tracking

versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.

Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.

CVE Severity Published Status Summary
CVE-2026-48165 HIGH (8.0) 2026-06-12 Current versionnot affected

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, a high-privileged MariaDB user could've used wsrep_sst_receive_address or wsrep_sst_donor global system variables to execute shell commands as the uid of the mariadbd process on the galera joiner node. This issue has been patched in versions 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2.

Affected versions
  • From (including) 10.6.1 - Up to (excluding) 10.6.27
  • From (including) 10.11.1 - Up to (excluding) 10.11.18
Show 2 more
  • From (including) 11.4.1 - Up to (excluding) 11.4.12
  • From (including) 11.8.1 - Up to (excluding) 11.8.8
CVE-2026-48163 HIGH (8.0) 2026-06-12 Current versionnot affected

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not all parameters were properly validated which could allow a malicious joiner to execute arbitrary shell commands on the donor side via the rsync SST method. This issue has been patched in versions 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2.

Affected versions
  • From (including) 10.6.1 - Up to (excluding) 10.6.27
  • From (including) 10.11.1 - Up to (excluding) 10.11.18
Show 2 more
  • From (including) 11.4.1 - Up to (excluding) 11.4.12
  • From (including) 11.8.1 - Up to (excluding) 11.8.8
CVE-2026-44172 CRITICAL (9.8) 2026-06-12 Current versionnot affected

MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9.

Affected versions
  • 3.3.18
  • 3.4.8
CVE-2026-44171 HIGH (7.8) 2026-06-12 Current versionnot affected

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, mbstream did not check for /../ in the path when unpacking the archive. A proper backup can never contain such paths, but a specially crafted archive could have caused mbstream to create files outside of the target-dir path. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.

Affected versions
  • From (including) 10.6.1 - Up to (excluding) 10.6.26
  • From (including) 10.11.1 - Up to (excluding) 10.11.17
Show 2 more
  • From (including) 11.4.1 - Up to (excluding) 11.4.11
  • From (including) 11.8.1 - Up to (excluding) 11.8.7
CVE-2026-44170 CRITICAL (9.8) 2026-06-12 Current versionnot affected

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB on WIndows with installed CONNECT engine and enabled REST support interpolated table HTTP attribute into the curl command line without proper sanitizing. This allows the user to execute shell commands on the server. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.

Affected versions
  • From (including) 10.6.1 - Up to (excluding) 10.6.26
  • From (including) 10.11.1 - Up to (excluding) 10.11.17
Show 2 more
  • From (including) 11.4.1 - Up to (excluding) 11.4.11
  • From (including) 11.8.1 - Up to (excluding) 11.8.7
CVE-2026-44168 HIGH (8.0) 2026-06-12 Current versionnot affected

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not all parameters were properly validated which could allow a malicious joiner to execute arbitrary shell commands on the donor side via the mariabackup SST method. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.

Affected versions
  • >= 10.6.1, < 10.6.26
  • >= 10.11.1, < 10.11.17
Show 3 more
  • >= 11.4.1, < 11.4.11
  • >= 11.8.1, < 11.8.7
  • >= 12.3.1, < 12.3.2
CVE-2026-49261 CRITICAL (10.0) 2026-06-11 Current versionnot affected

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.

Affected versions
  • >= 10.6.1, < 10.6.27
  • >= 10.11.1, < 10.11.18
Show 3 more
  • >= 11.4.1, < 11.4.12
  • >= 11.8.1, < 11.8.8
  • = 12.3.1
CVE-2026-32710 CRITICAL (9.9) 2026-03-20 Current versionnot affected

MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possible to turn the crash into a remote code execution. These conditions require tight control over memory layout which is generally only attainable in a lab environment. This issue is fixed in MariaDB 11.4.10, MariaDB 11.8.6, and MariaDB 12.2.2.

Affected versions
  • From (including) 11.4.1 - Up to (excluding) 11.4.10
  • From (including) 11.8.1 - Up to (excluding) 11.8.6