VulnSea

samba vulnerabilities

CVEs whose affected-version data names the samba package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2026-58224Medium· 6.5
1mo ago

A flaw was found in Samba's CTDB, the clustered database service used by Samba

A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets allows malformed packets containing invalid field lengths, improperly terminated strings,…

Sunlitsamba · sambaEPSS 0.29%via NVD
CVE-2026-4408Critical· 9.0PoC
3mo ago

A flaw was found in Samba

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution characte…

Abyssalredhat · openshift_container_platformEPSS 2.5%via NVD
CVE-2026-2340Medium· 6.5
3mo ago

A flaw was found in Samba’s vfs_worm module

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename o…

Sunlitredhat · openshift_container_platformEPSS 0.94%via NVD
CVE-2026-1933High· 7.1
3mo ago

A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes

A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete re…

Twilightredhat · openshift_container_platformEPSS 0.86%via NVD
CVE-2026-3012High· 8.0
3mo ago

A flaw was found in Samba’s certificate auto-enrollment Group Policy handling

A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store…

Twilightredhat · openshift_container_platformEPSS 0.26%via NVD
CVE-2025-0620Medium· 4.9
1y ago

A flaw was found in Samba

A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.

Sunlitsamba · sambaEPSS 0.75%via NVD
samba vulnerabilities (CVEs) · VulnSea