CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

USN-8536-1: MariaDB vulnerabilities

highCVE-2026-44168CVE-2026-44169CVE-2026-44171CVE-2026-44172CVE-2026-44173CVE-2026-48163
It was discovered that MariaDB did not properly validate parameters supplied by a joiner node during a State Snapshot Transfer using the mariabackup method. An attacker could possibly use this issue to execute arbitrary shell commands on the donor node. (CVE-2026-44168) It was discovered that MariaDB did not properly enforce the SHOW CREATE ROUTINE privilege when a user obtained access to a stored routine via a role. An authenticated user could possibly use this issue to obtain sensitive information. (CVE-2026-44169) It was discovered that MariaDB's mbstream utility did not properly validate paths when unpacking archives. An attacker could possibly use this issue to write files outside of the intended target directory. (CVE-2026-44171) It was discovered that MariaDB's mysql_real_escape_string() function incorrectly handled the big5 character set. An attacker could possibly use this issue to perform SQL injection attacks. (CVE-2026-44172) It was discovered that MariaDB did not properly check the FILE privilege when the FROM clause of a SELECT ... INTO OUTFILE or SELECT ... INTO DUMPFILE statement contained only subqueries. An authenticated user could possibly use this issue to write files to unintended locations. (CVE-2026-44173) It was discovered that MariaDB did not properly validate parameters supplied by a joiner node during a State Snapshot Transfer using the rsync method. An attacker could possibly use this issue to execute arbitrary shell commands on the donor node. (CVE-2026-48163) It was discovered that MariaDB allowed a high-privileged user to set certain Galera system variables to values containing shell commands, which were then executed by the server process. An authenticated user could possibly use this issue to execute arbitrary shell commands. (CVE-2026-48165) It was discovered that MariaDB executed shell commands embedded in the name of a joiner node when wsrep_notify_cmd was enabled. A remote attacker could possibly use this issue to execute arbitra

CSIRTS triage

What
Multiple vulnerabilities in MariaDB could allow an attacker to execute arbitrary shell commands, disclose sensitive information, and write files outside intended directories.
Who is affected
All deployments of MariaDB are affected.
Urgency
Remediation is urgent due to the high severity of the vulnerabilities.
Action
Users should update to the latest version of MariaDB.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch MariaDB

Get an email when a new MariaDB advisory drops — max one per day, one-click unsubscribe.

Details

Source
Ubuntu Security Notices (INTL · vendor-psirt · site)
Severity
high
Published
2026-07-14
Exploitation
Not in CISA KEV at last sync

Original advisory: https://ubuntu.com/security/notices/USN-8536-1

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-44168coverage & exploitation statusNVD · CVE.org
CVE-2026-44169coverage & exploitation statusNVD · CVE.org
CVE-2026-44171coverage & exploitation statusNVD · CVE.org
CVE-2026-44172coverage & exploitation statusNVD · CVE.org
CVE-2026-44173coverage & exploitation statusNVD · CVE.org
CVE-2026-48163coverage & exploitation statusNVD · CVE.org
CVE-2026-48165coverage & exploitation statusNVD · CVE.org
CVE-2026-49261coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Ubuntu Security Notices