CVE-2026-47847 Details
Description
Bitnami MariaDB Galera container images and Helm chart are affected by a hardcoded default credential vulnerability in the Galera replication health-check user. The MARIADB_REPLICATION_USER and MARIADB_REPLICATION_PASSWORD environment variables defaulted to monitor and monitor respectively. This user is granted REPLICATION CLIENT privileges from any host ('%'). The Bitnami Helm chart for MariaDB Galera did not expose parameters to configure this user's credentials, resulting in all chart deployments using this publicly known credential by default. Affected versions — Container image: 10.6.x prior to 10.6.27-photon-5-r0; 10.11.x prior to 10.11.17-photon-5-r1; 11.4.x prior to 11.4.12-photon-5-r0; 11.8.x prior to 11.8.7-photon-5-r1; 12.3.x prior to 12.3.2-photon-5-r0 / 12.3.2-debian-12-r0. Helm chart: prior to 18.3.0.
A vulnerability exists in Bitnami MariaDB Galera container images and Helm chart versions prior to 18.3.0, due to hardcoded default credentials for the Galera replication health-check user. The environment variables MARIADB_REPLICATION_USER and MARIADB_REPLICATION_PASSWORD default to 'monitor' and 'monitor', respectively. This user has REPLICATION CLIENT privileges from any host. The default credentials are publicly known, and the Helm chart does not allow customization of these values, leading to potential unauthorized access to replication metadata and cluster topology.
Users of the Bitnami MariaDB Galera container images should upgrade to version 10.6.27-photon-5-r0, 10.11.17-photon-5-r1, 11.4.12-photon-5-r0, 11.8.7-photon-5-r1, or 12.3.2-photon-5-r0 / 12.3.2-debian-12-r0. Helm chart users should upgrade to version 18.3.0 or later. After upgrading, it's recommended to set the replication password to a strong, unique value. For existing deployments, the replication user password should be rotated by connecting as root and executing the appropriate ALTER USER command.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/bitnami/containers/security/advisories/GHSA-xcv9-cg8m-3mf2 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 18, 2026 | CVE Modified | CISA-ADP |
| Jun 18, 2026 | New CVE Received | [email protected] |