CVE-2026-4408
קריטית 9.8
תיאור (מקור, אנגלית)
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 3% (אחוזון 100) נכון ל-6/8/2026
- CWE
- CWE-78
מוצרים מושפעים
redhat: openshift container platform; samba: samba; redhat: enterprise linux
קישורים
- https://bugzilla.samba.org/show_bug.cgi?id=16034 Issue TrackingVendor Advisory
- https://access.redhat.com/errata/RHSA-2026:22644 Issue Tracking
- https://access.redhat.com/errata/RHSA-2026:22963 Issue Tracking
- https://access.redhat.com/errata/RHSA-2026:25049
- https://access.redhat.com/errata/RHSA-2026:25979
- https://access.redhat.com/errata/RHSA-2026:28053
- https://access.redhat.com/errata/RHSA-2026:28054
- https://access.redhat.com/errata/RHSA-2026:28055
- https://access.redhat.com/errata/RHSA-2026:28056
- https://access.redhat.com/errata/RHSA-2026:28057