AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-27928

HIGH · CVSS 7.2 EPSS 38.18% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-03-19 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution
External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2021-27928
Severity
HIGH
CVSS
7.2
EPSS
38.18%
Oracle

Original NVD Description

A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. An untrusted search path leads to eval injection, in which a database SUPER user can execute OS commands after modifying wsrep_provider and wsrep_notify_cmd. NOTE: this does not affect an Oracle product.