Logo
vulnerabilityCVE-2026-3012
Name
CVE-2026-3012
Source
NVD ( link)Debian ( link)
Description
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
samba
Exploitable

Vulnerability Ratings#


8
CVSSv31
6.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
4.22.10
Not Affected
buildroot
master
4.24.3
Not Affected
openwrt
master
4.22.7-r3
Not Affected
openwrt
openwrt-25.12
4.22.7-r3
Not Affected
yocto
kirkstone
4.14.14
Not Affected
yocto
master
4.23.5
Not Affected