CVE-2026-2340
published 2026-05-27CVE-2026-2340: A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files…
PriorityP343medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.94%
56.9th percentile
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
| samba | samba | — | — |
| samba | samba | >= 4.1.0 | — |
| ubuntu | samba | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
vendor_ubuntu8.5HIGH
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
samba: vfs_worm does not block directory modification
vendor_redhat·2026-05-27·CVSS 6.5
CVE-2026-2340 [MEDIUM] CWE-280 samba: vfs_worm does not block directory modification
samba: vfs_worm does not block directory modification
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.
Statement: This vulnerability is rated Moderate severity because exploitation requires authenticated write access to a Samba share already configured to permit file creation and modification.
The flaw affects the vfs_worm module, which provides additional immutability protections for files after a configurable grace period. Due to imprope
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2026-05-26·CVSS 8.5
CVE-2026-4480 [HIGH] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Asim Viladi Oglu Manizada discovered that Samba incorrectly handled access
checks on reparse point operations. An attacker could possibly use this
issue to modify reparse point extended attributes on files that should have
been read-only. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.
(CVE-2026-1933)
Pavel Kohout discovered that Samba's vfs_worm module did not properly block
file overwrites. An attacker could possibly use this issue to overwrite
files that should have remained immutable. (CVE-2026-2340)
Arad Inbar, Nir Somech, and Ben Grinberg discovered that Samba incorrectly
handled certificate auto-enrolment group policies over HTTP without
verification. A machine-in-the-middle attacker c
GHSA
GHSA-m6w2-p258-gxqp: A flaw was found in Samba’s vfs_worm module
ghsa_unreviewed·2026-05-27
CVE-2026-2340 [MEDIUM] CWE-280 GHSA-m6w2-p258-gxqp: A flaw was found in Samba’s vfs_worm module
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-2340 samba: vfs_worm does not block directory modification [fedora-all]
bugzilla·2026-05-27·CVSS 6.5
CVE-2026-2340 [MEDIUM] CVE-2026-2340 samba: vfs_worm does not block directory modification [fedora-all]
CVE-2026-2340 samba: vfs_worm does not block directory modification [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-2340 samba: vfs_worm does not block directory modification
bugzilla·2026-03-13·CVSS 6.5
CVE-2026-2340 [MEDIUM] CVE-2026-2340 samba: vfs_worm does not block directory modification
CVE-2026-2340 samba: vfs_worm does not block directory modification
Samba: vfs_worm does not block directory modification
Discussion:
Embargo lifted. The CVE is now public.
https://www.samba.org/samba/security/CVE-2026-2340.html
https://bugzilla.samba.org/show_bug.cgi?id=15997
https://access.redhat.com/errata/RHSA-2026:22644https://access.redhat.com/errata/RHSA-2026:22963https://access.redhat.com/errata/RHSA-2026:25049https://access.redhat.com/errata/RHSA-2026:25979https://access.redhat.com/errata/RHSA-2026:28053https://access.redhat.com/errata/RHSA-2026:28054https://access.redhat.com/errata/RHSA-2026:28055https://access.redhat.com/errata/RHSA-2026:28056https://access.redhat.com/errata/RHSA-2026:28057https://access.redhat.com/errata/RHSA-2026:29863https://access.redhat.com/security/cve/CVE-2026-2340https://bugzilla.redhat.com/show_bug.cgi?id=2447318https://bugzilla.samba.org/show_bug.cgi?id=15997
2026-05-27
Published