Logo
vulnerabilityCVE-2026-4408
Name
CVE-2026-4408
Source
NVD ( link)Debian ( link)
Description
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
samba
Exploitable

Vulnerability Ratings#


9
CVSSv31
9.8
CVSSv31
9
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
4.22.11
Not Affected
buildroot
master
4.24.6
Not Affected
openwrt
master
4.24.5-r1
Not Affected
openwrt
openwrt-25.12
4.22.7-r3
Not Affected
yocto
master
4.23.11
Not Affected
yocto
scarthgap
4.19.9
Patched

Resolved with patches#


samba (yocto:scarthgap)

#
Title
Author
Resolve
1
CVE-2026-4408: s3:samr-server: deny, mask and/or single
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
2
CVE-2026-4480/CVE-2026-4408: lib/util: factor out a
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
3
CVE-2026-4480/CVE-2026-4408: lib/util: add
Douglas Bagnall <douglas.bagnall@catalyst.net.nz>
CVE-2026-4408
4
CVE-2026-4480/CVE-2026-4408: lib/util: let
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
5
CVE-2026-4408: s3:samr-server: only allow
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
6
CVE-2026-4480/CVE-2026-4408: lib/util: add
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
7
CVE-2026-4480/CVE-2026-4408: lib/util: let log_escape()
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
8
CVE-2026-4408: lib/util: introduce
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
9
CVE-2026-4480/CVE-2026-4408: lib/util: split out
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
10
CVE-2026-4480/CVE-2026-4408: s3:lib: fix potential
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
11
CVE-2026-4408: docs-xml/smbdotconf: clarify '%u' in
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
12
CVE-2026-4480/CVE-2026-4408: lib/util: remove unused
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
13
CVE-2026-4480/CVE-2026-4408: s3:lib: let
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
14
CVE-2026-4408: s3:testparm: warn about 'check password
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
15
CVE-2026-4408: s3:samr-server: make
Douglas Bagnall <douglas.bagnall@catalyst.net.nz>
CVE-2026-4408
16
CVE-2026-4480/CVE-2026-4408: lib/util: add more unsafe
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
17
CVE-2026-4480/CVE-2026-4408: lib/util: inline
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
18
CVE-2026-4408: s3:torture: tests for password
Douglas Bagnall <douglas.bagnall@catalyst.net.nz>
CVE-2026-4408