USN-8536-1: MariaDB vulnerabilities
It was discovered that MariaDB did not properly validate parameters supplied by a joiner node during a State Snapshot Transfer using the mariabackup method. An attacker could possibly use this issue to execute arbitrary shell commands on the donor node. (CVE-2026-44168) It was discovered that MariaDB did not properly enforce the SHOW CREATE ROUTINE privilege when a user obtained access to a stored routine via a role. An authenticated user could possibly use this issue to obtain sensitive information. (CVE-2026-44169) It was discovered that MariaDB's mbstream utility did not properly validate paths when unpacking archives. An attacker could possibly use this issue to write files outside of the intended target directory. (CVE-2026-44171) It was discovered that MariaDB's mysql_real_escape_string() function incorrectly handled the big5 character set. An attacker could possibly use this issue to perform SQL injection attacks. (CVE-2026-44172) It was discovered that MariaDB did not properly check the FILE privilege when the FROM clause of a SELECT ... INTO OUTFILE or SELECT ... INTO DUMPFILE statement contained only subqueries. An authenticated user could possibly use this issue to write files to unintended locations. (CVE-2026-44173) It was discovered that MariaDB did not properly validate parameters supplied by a joiner node during a State Snapshot Transfer using the rsync method. An attacker could possibly use this issue to execute arbitrary shell commands on the donor node. (CVE-2026-48163) It was discovered that MariaDB allowed a high-privileged user to set certain Galera system variables to values containing shell commands, which were then executed by the server process. An authenticated user could possibly use this issue to execute arbitrary shell commands. (CVE-2026-48165) It was discovered that MariaDB executed shell commands embedded in the name of a joiner node when wsrep_notify_cmd was enabled. A remote attacker could possibly use this issue to execute arbitra
CSIRTS triage
- What
- Multiple vulnerabilities in MariaDB could allow an attacker to execute arbitrary shell commands, disclose sensitive information, and write files outside intended directories.
- Who is affected
- All deployments of MariaDB are affected.
- Urgency
- Remediation is urgent due to the high severity of the vulnerabilities.
- Action
- Users should update to the latest version of MariaDB.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch MariaDB
Get an email when a new MariaDB advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8536-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-441680.57% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 44% of all scored CVEs.
- Low exploitation riskCVE-2026-441690.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
- Low exploitation riskCVE-2026-441710.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
- Low exploitation riskCVE-2026-441720.59% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all scored CVEs.
- Low exploitation riskCVE-2026-441730.55% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all scored CVEs.
- Low exploitation riskCVE-2026-481630.88% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 56% of all scored CVEs.
- Moderate exploitation riskCVE-2026-481651.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 69% of all scored CVEs.
- Moderate exploitation riskCVE-2026-492611.4% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 70% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-44168 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-44169 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-44171 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-44172 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-44173 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48163 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48165 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-49261 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from Ubuntu Security Notices
- highUSN-8620-4: Linux kernel (Intel IoTG) vulnerabilities2026-07-31
- highUSN-8620-3: Linux kernel (Intel IoTG) vulnerabilities2026-07-31
- unknownUSN-8625-1: OpenSSL vulnerability2026-07-30
- unknownUSN-8624-1: Sinatra vulnerability2026-07-29
- unknownUSN-8623-1: Linux kernel (NVIDIA) vulnerabilities2026-07-29