---
id: CVE-2026-4408
title: A flaw was found in Samba
summary: >-
  A flaw was found in Samba. A remote attacker can exploit a misconfiguration in
  Samba file servers and classic domain controllers that use the "check password
  script" feature. If this script is configured with the %u substitution
  characte…
severity: critical
cvss: 9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: redhat
product: openshift_container_platform
affected:
  - openshift_container_platform = 4.0
  - 'samba >= 4.1.0, < 4.21.0'
  - enterprise_linux = 6.0
  - enterprise_linux = 7.0
  - enterprise_linux = 9.0
patched:
  - samba 4.21.0
published: '2026-05-28'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T13:18:31.373'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-4408'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:22644'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:22963'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:25049'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:25979'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:28053'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:28054'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:28055'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:28056'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:28057'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:28058'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:28132'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:29799'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:29833'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:29863'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:56786'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:56853'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:56911'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:57483'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:59831'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:60019'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:65839'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-4408'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2479762'
    label: secalert@redhat.com
  - url: 'https://bugzilla.samba.org/show_bug.cgi?id=16034'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:22644'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22963'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:25049'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:25979'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:28053'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:28054'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:28055'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:28056'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:28057'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:28058'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:28132'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:29799'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:29833'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:29863'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:56786'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:56853'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:56911'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:57483'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:59831'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60019'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:65839'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-4408'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2479762'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4408.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-4408'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-4408'
tags:
  - nvd
  - exploit-available
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.0175
epssPercentile: 0.76851
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/SafeBreach-Labs/ForgottenButNotGone'
  checkedAt: '2026-09-25T08:20:57.486Z'
exploitAvailable: true
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-05-29T03:55:49.995145Z'
ingestedAt: '2026-07-01T09:50:45.867Z'
---

## Overview

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.

## Affected

- `openshift_container_platform = 4.0`
- `samba >= 4.1.0, < 4.21.0`
- `enterprise_linux = 6.0`
- `enterprise_linux = 7.0`
- `enterprise_linux = 9.0`

## Remediation

Upgrade past the affected range:

- `samba 4.21.0`

## Vendor advisories

- **RHSA-2026:28132** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7 ELS), Red Hat Enterprise Linux Server ResilientStorage (v. 7 ELS), Red Hat Enterprise Linux Server Optional (v. 7 ELS) · released 2026-06-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:28132)
- **RHSA-2026:59831** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.12 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:59831)
- **RHSA-2026:65839** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.13 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:65839)
- **RHSA-2026:56786** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.14 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:56786)
- **RHSA-2026:56911** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.15 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:56911)
- **RHSA-2026:56853** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.16 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:56853)
- **RHSA-2026:60019** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.17 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:60019)
- **RHSA-2026:57483** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.18 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:57483)
- **RHSA-2026:29863** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.19 · released 2026-07-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:29863)
- **RHSA-2026:29799** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.20 · released 2026-06-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:29799)
- **RHSA-2026:29833** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.21 · released 2026-06-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:29833)
- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 6, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat OpenShift Container Platform 4 · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4408.json)
