Description
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected products
- RedHat / enterprise_linux6.0 – 6.0
- RedHat / enterprise_linux7.0 – 7.0
- RedHat / enterprise_linux9.0 – 9.0
- RedHat / openshift_container_platform4.0 – 4.0
- Samba / Samba4.1.0 – 4.21.0
References
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:22644
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:22963
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:25049
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:25979
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:28053
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:28054
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:28055
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:28056
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:28057
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:28058
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:28132
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:29799
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:29833
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:29863
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:57483
- VENDOR_ADVISORYhttps://access.redhat.com/security/cve/CVE-2026-4408
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=2479762
- MISChttps://bugzilla.samba.org/show_bug.cgi?id=16034
Updated 5m ago · 8 sources