CVE-2026-4408Critical· 9.0▾ AbyssalPoC availableA flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution characte…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 49.5 · likelihood 0.5 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
2.5%
1 GitHub repo
Last analysed / modified upstream
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.
openshift_container_platform = 4.0samba >= 4.1.0, < 4.21.0enterprise_linux = 6.0enterprise_linux = 7.0enterprise_linux = 9.0Upgrade past the affected range:
samba 4.21.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-2340Medium· 6.5A flaw was found in Samba’s vfs_worm module
CVE-2026-1933High· 7.1A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes
CVE-2026-3012High· 8.0A flaw was found in Samba’s certificate auto-enrollment Group Policy handling
CVE-2026-42965High· 7.7A flaw was found in the OpenShift Router
CVE-2026-54100High· 8.3A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform
CVE-2026-54099High· 8.8A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform