---
title: "MariaDB Enterprise Server Q1 2026 Corrective Releases"
publish_date: 2026-06-02
author: "Daniel Bartholomew"
channel:
  - name: "Product"
    url: "/ja/resources/blog/channel/product.md"
tags:
  - name: "MariaDB Enterprise"
    url: "/resources/blog/tag/mariadb-enterprise.md"
---

# MariaDB Enterprise Server Q1 2026 Corrective Releases

New corrective maintenance releases for MariaDB Enterprise Server 11.8.6-4, 11.4.10-8, and 10.6.25-22 are now available.

[Download Now](https://mariadb.com/downloads/enterprise/enterprise-server/)

### Notable Release Updates

- A parameter-injection gap existed in wsrep\_sst\_rsync because it failed to validate the joiner-supplied WSREP\_SST\_OPT\_REMOTE\_USER and WSREP\_SST\_OPT\_REMOTE\_PSWD values before interpolating them into the donor-written stunnel.conf and the rsync magic file
- An appropriately privileged user (with SUPER privileges) could execute shell commands as the uid of the mariadbd process because the values of the system variables wsrep\_sst\_donor and wsrep\_sst\_receive\_address, which can be modified at runtime, were not properly sanitized when used to construct a shell command
- The wsrep\_notify\_cmd functionality was susceptible to a parameter-injection vulnerability, as it failed to validate the peer-supplied wsrep\_node\_name and wsrep\_node\_incoming\_address values before interpolating them into the notification command line

### Release Notes

- [MariaDB Enterprise Server 11.8.6-4 Release Notes](https://mariadb.com/docs/release-notes/enterprise-server/11.8/11.8.6-4)
- [MariaDB Enterprise Server 11.4.10-8 Release Notes](https://mariadb.com/docs/release-notes/enterprise-server/11.4/11.4.10-8)
- [MariaDB Enterprise Server 10.6.25-22 Release Notes](https://mariadb.com/docs/release-notes/enterprise-server/10.6/10.6.25-22)

### Why MariaDB Enterprise Server

[MariaDB Enterprise Server](https://mariadb.com/products/enterprise/components/) is an enhanced, hardened and secured version of [MariaDB Community Server](https://mariadb.com/products/community-server/) that delivers enterprise reliability, stability and long-term support as well as greater operational efficiency when it comes to managing large database deployments for business and mission critical applications. MariaDB Enterprise Server offers additional features needed for production workloads that are not available in the community edition, such as [Enterprise Audit](https://mariadb.com/docs/security/mariadb-enterprise-audit/) and [Enterprise Backup](https://mariadb.com/docs/recovery/mariadb-enterprise-backup/), and also backports certain enterprise features to older versions so customers can take advantage of critical fixes and features immediately instead of having to upgrade to the newest version.

Being able to backport features from newer release series to older versions is a key advantage of MariaDB Enterprise Server. Quality assurance and internal processes do not always allow customers to upgrade production environments to the newest and greatest release series, although some of the new features would be of value. MariaDB Enterprise Server can help in this case, as we can backport highly requested features to existing versions in cases where we can assure that a backported feature does not decrease the stability of that release series of MariaDB Enterprise Server.

### Download MariaDB Enterprise Server

MariaDB customers can download MariaDB Enterprise Server versions at [mariadb.com/downloads/enterprise](https://mariadb.com/downloads/enterprise/).