CVE-2026-1933
published 2026-05-27CVE-2026-1933: A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks…
PriorityP343medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.86%
54.8th percentile
A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations even on read-only exports. This could allow modification of SMB-visible file behavior, including converting files into symbolic links or other reparse point types.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
| samba | samba | — | — |
| samba | samba | >= 4.1.0 < 4.2.2 | 4.2.2 |
| ubuntu | samba | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
vendor_redhat8.8HIGH
vendor_ubuntu8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
samba: Missing access check on reparse point operations
vendor_redhat·2026-05-27·CVSS 7.1
CVE-2026-1933 [HIGH] CWE-284 samba: Missing access check on reparse point operations
samba: Missing access check on reparse point operations
A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations even on read-only exports. This could allow modification of SMB-visible file behavior, including converting files into symbolic links or other reparse point types.
Statement: This vulnerability is rated Important severity by Red Hat Product Security, because authenticated users with filesystem-level write permissions may bypass Samba’s SMB-layer read-only protections for reparse point operations.
The flaw affects shares configured with "read only = yes", wh
Red Hat
jenkins-email-extension-plugin: Jenkins Email Extension Plugin: Information disclosure via arbitrary file read
vendor_redhat·2026-05-27·CVSS 8.8
CVE-2026-48920 [HIGH] CWE-22 jenkins-email-extension-plugin: Jenkins Email Extension Plugin: Information disclosure via arbitrary file read
jenkins-email-extension-plugin: Jenkins Email Extension Plugin: Information disclosure via arbitrary file read
Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify `file:` URLs for images to read arbitrary files from the Jenkins controller filesystem.
A flaw was found in the Jenkins Email Extension Plugin. An attacker with the ability to control email content can exploit this vulnerability by inlining images with `file:` URLs. This allows the attacker to read arbitrary files from the Jenkins controller filesystem, leading to information disclosure.
Package: jenkins-
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2026-05-26·CVSS 8.5
CVE-2026-4480 [HIGH] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Asim Viladi Oglu Manizada discovered that Samba incorrectly handled access
checks on reparse point operations. An attacker could possibly use this
issue to modify reparse point extended attributes on files that should have
been read-only. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.
(CVE-2026-1933)
Pavel Kohout discovered that Samba's vfs_worm module did not properly block
file overwrites. An attacker could possibly use this issue to overwrite
files that should have remained immutable. (CVE-2026-2340)
Arad Inbar, Nir Somech, and Ben Grinberg discovered that Samba incorrectly
handled certificate auto-enrolment group policies over HTTP without
verification. A machine-in-the-middle attacker c
VulDB
Samba NTFS access control (Nessus ID 316851)
vuldb·2026-06-07·CVSS 6.5
CVE-2026-1933 [MEDIUM] Samba NTFS access control (Nessus ID 316851)
A vulnerability marked as critical has been reported in Samba. Affected is an unknown function of the component NTFS Handler. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2026-1933. The attack is possible to be carried out remotely. No exploit exists.
GHSA
GHSA-c866-5hw6-cqf9: A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes
ghsa_unreviewed·2026-05-27
CVE-2026-1933 [HIGH] CWE-284 GHSA-c866-5hw6-cqf9: A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes
A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations even on read-only exports. This could allow modification of SMB-visible file behavior, including converting files into symbolic links or other reparse point types.
GHSA
Jenkins Email Extension Plugin: Attackers able to control email content may specify `file:` URLs for images to read arbitrary files from Jenkins controller filesystem
ghsa·2026-05-27
CVE-2026-48920 [HIGH] CWE-73 Jenkins Email Extension Plugin: Attackers able to control email content may specify `file:` URLs for images to read arbitrary files from Jenkins controller filesystem
Jenkins Email Extension Plugin: Attackers able to control email content may specify `file:` URLs for images to read arbitrary files from Jenkins controller filesystem
Jenkins Email Extension Plugin 1933.v45cec755423f and earlier includes a feature that allows inlining images as `base64` in email content by setting the `data-inline` attribute. No restrictions are placed on the image URLs that can be inlined.
This allows attackers able to control the email content to specify `file:` URLs for images to read arbitrary files from the Jenkins controller filesystem.
The feature allowing inlining images as `base64` in email content by setting the `data-inline` attribute is removed from Email Extension Plugin 1933.1935.v276319e3cc47.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-1933 samba: Missing access check on reparse point operations [fedora-all]
bugzilla·2026-05-27·CVSS 7.1
CVE-2026-1933 [HIGH] CVE-2026-1933 samba: Missing access check on reparse point operations [fedora-all]
CVE-2026-1933 samba: Missing access check on reparse point operations [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-48920 jenkins-email-extension-plugin: Jenkins Email Extension Plugin: Information disclosure via arbitrary file read
bugzilla·2026-05-27·CVSS 8.8
CVE-2026-48920 [HIGH] CVE-2026-48920 jenkins-email-extension-plugin: Jenkins Email Extension Plugin: Information disclosure via arbitrary file read
CVE-2026-48920 jenkins-email-extension-plugin: Jenkins Email Extension Plugin: Information disclosure via arbitrary file read
Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify `file:` URLs for images to read arbitrary files from the Jenkins controller filesystem.
Bugzilla
CVE-2026-1933 samba: Missing access check on reparse point operations
bugzilla·2026-03-13·CVSS 7.1
CVE-2026-1933 [HIGH] CVE-2026-1933 samba: Missing access check on reparse point operations
CVE-2026-1933 samba: Missing access check on reparse point operations
Samba: Missing access check on reparse point operations
Discussion:
Embargo Lifted. The CVE is now public.
https://www.samba.org/samba/security/CVE-2026-1933.html
https://bugzilla.samba.org/show_bug.cgi?id=15992
https://access.redhat.com/errata/RHSA-2026:22644https://access.redhat.com/errata/RHSA-2026:22963https://access.redhat.com/errata/RHSA-2026:25049https://access.redhat.com/errata/RHSA-2026:25979https://access.redhat.com/errata/RHSA-2026:28053https://access.redhat.com/errata/RHSA-2026:28054https://access.redhat.com/errata/RHSA-2026:28055https://access.redhat.com/errata/RHSA-2026:28056https://access.redhat.com/errata/RHSA-2026:28057https://access.redhat.com/errata/RHSA-2026:29863https://access.redhat.com/security/cve/CVE-2026-1933https://bugzilla.redhat.com/show_bug.cgi?id=2447317https://bugzilla.samba.org/show_bug.cgi?id=15992https://access.redhat.com/errata/RHSA-2026:22644https://access.redhat.com/errata/RHSA-2026:22963https://access.redhat.com/errata/RHSA-2026:25049https://access.redhat.com/errata/RHSA-2026:25979https://access.redhat.com/errata/RHSA-2026:28053https://access.redhat.com/errata/RHSA-2026:28054https://access.redhat.com/errata/RHSA-2026:28055https://access.redhat.com/errata/RHSA-2026:28056https://access.redhat.com/errata/RHSA-2026:28057https://access.redhat.com/errata/RHSA-2026:29863https://access.redhat.com/security/cve/CVE-2026-1933https://bugzilla.redhat.com/show_bug.cgi?id=2447317https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1933.json
2026-05-27
Published