---
id: CVE-2026-1933
title: >-
  A flaw was found in Samba’s handling of NTFS-style reparse points on shares
  configured with read only = yes
summary: >-
  A flaw was found in Samba’s handling of NTFS-style reparse points on shares
  configured with read only = yes. Due to missing SMB-layer access checks,
  authenticated users with underlying filesystem write permissions may create or
  delete re…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H'
cwe:
  - CWE-284
vendor: redhat
product: openshift_container_platform
affected:
  - openshift_container_platform = 4.0
  - 'samba >= 4.1.0, < 4.2.2'
  - enterprise_linux = 7.0
  - enterprise_linux = 8.0
  - enterprise_linux = 9.0
  - enterprise_linux = 10.0
patched:
  - samba 4.2.2
published: '2026-05-27'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T13:17:25.807'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-1933'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:22644'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:22963'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:25049'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:25979'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:28053'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:28054'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:28055'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:28056'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:28057'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:29863'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:54581'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:54599'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:54769'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:56786'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:56853'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:56911'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:57483'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:59831'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:60019'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:65839'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-1933'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2447317'
    label: secalert@redhat.com
  - url: 'https://bugzilla.samba.org/show_bug.cgi?id=15992'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:22644'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22963'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:25049'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:25979'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:28053'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:28054'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:28055'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:28056'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:28057'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:29863'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:54581'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:54599'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:54769'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:56786'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:56853'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:56911'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:57483'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:59831'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60019'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:65839'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-1933'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2447317'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1933.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-1933'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-1933'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00862
epssPercentile: 0.5706
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-05-27T14:40:45.546157Z'
ingestedAt: '2026-07-03T13:02:27.458Z'
---

## Overview

A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations even on read-only exports. This could allow modification of SMB-visible file behavior, including converting files into symbolic links or other reparse point types.

## Affected

- `openshift_container_platform = 4.0`
- `samba >= 4.1.0, < 4.2.2`
- `enterprise_linux = 7.0`
- `enterprise_linux = 8.0`
- `enterprise_linux = 9.0`
- `enterprise_linux = 10.0`

## Remediation

Upgrade past the affected range:

- `samba 4.2.2`

## Vendor advisories

- **RHSA-2026:59831** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.12 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:59831)
- **RHSA-2026:65839** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.13 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:65839)
- **RHSA-2026:56786** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.14 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:56786)
- **RHSA-2026:56911** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.15 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:56911)
- **RHSA-2026:56853** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.16 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:56853)
- **RHSA-2026:60019** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.17 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:60019)
- **RHSA-2026:57483** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.18 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:57483)
- **RHSA-2026:29863** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.19 · released 2026-07-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:29863)
- **RHSA-2026:54581** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.20 · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:54581)
- **RHSA-2026:54599** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.21 · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:54599)
- **RHSA-2026:54769** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.22 · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:54769)
- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat OpenShift Container Platform 4 · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1933.json)
