CVE-2026-3012
published 2026-05-27CVE-2026-3012: A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate…
PriorityP335medium6.8CVSS 3.1
AVAACHPRNUINSUCHIHAN
EPSS
0.26%
17.7th percentile
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
| samba | samba | — | — |
| samba | samba | >= 4.16.0 < 4.21.0 | 4.21.0 |
| ubuntu | samba | — | — |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_ubuntu8.5HIGH
vendor_redhat8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
samba: group policy certificate enrollment uses http:// without validation
vendor_redhat·2026-05-27·CVSS 8.0
CVE-2026-3012 [HIGH] CWE-345 samba: group policy certificate enrollment uses http:// without validation
samba: group policy certificate enrollment uses http:// without validation
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.
Statement: Red Hat Product Security has rated this vulnerability as Important severity.
However, exploitation requires several specific non-default conditions to be met. The vulnerable code path is only reachable when Samba Grou
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2026-05-26·CVSS 8.5
CVE-2026-4480 [HIGH] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Asim Viladi Oglu Manizada discovered that Samba incorrectly handled access
checks on reparse point operations. An attacker could possibly use this
issue to modify reparse point extended attributes on files that should have
been read-only. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.
(CVE-2026-1933)
Pavel Kohout discovered that Samba's vfs_worm module did not properly block
file overwrites. An attacker could possibly use this issue to overwrite
files that should have remained immutable. (CVE-2026-2340)
Arad Inbar, Nir Somech, and Ben Grinberg discovered that Samba incorrectly
handled certificate auto-enrolment group policies over HTTP without
verification. A machine-in-the-middle attacker c
GHSA
GHSA-59rx-q76w-hqrw: A flaw was found in Samba’s certificate auto-enrollment Group Policy handling
ghsa_unreviewed·2026-05-27
CVE-2026-3012 [HIGH] CWE-345 GHSA-59rx-q76w-hqrw: A flaw was found in Samba’s certificate auto-enrollment Group Policy handling
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-3012 samba: group policy certificate enrollment uses http:// without validation [fedora-all]
bugzilla·2026-05-27·CVSS 8.0
CVE-2026-3012 [HIGH] CVE-2026-3012 samba: group policy certificate enrollment uses http:// without validation [fedora-all]
CVE-2026-3012 samba: group policy certificate enrollment uses http:// without validation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-3012 samba: group policy certificate enrollment uses http:// without validation
bugzilla·2026-03-13·CVSS 8.0
CVE-2026-3012 [HIGH] CVE-2026-3012 samba: group policy certificate enrollment uses http:// without validation
CVE-2026-3012 samba: group policy certificate enrollment uses http:// without validation
Samba: group policy certificate enrollment uses http:// without validation
Discussion:
Embargo Lifted. The CVE is public now:
https://bugzilla.samba.org/show_bug.cgi?id=16003
https://attachments.samba.org/attachment.cgi?id=18990
https://access.redhat.com/errata/RHSA-2026:22644https://access.redhat.com/errata/RHSA-2026:22963https://access.redhat.com/errata/RHSA-2026:25049https://access.redhat.com/errata/RHSA-2026:25979https://access.redhat.com/errata/RHSA-2026:28053https://access.redhat.com/errata/RHSA-2026:28054https://access.redhat.com/errata/RHSA-2026:28055https://access.redhat.com/errata/RHSA-2026:28056https://access.redhat.com/errata/RHSA-2026:28057https://access.redhat.com/errata/RHSA-2026:29863https://access.redhat.com/security/cve/CVE-2026-3012https://bugzilla.redhat.com/show_bug.cgi?id=2447319https://bugzilla.samba.org/show_bug.cgi?id=16003https://access.redhat.com/errata/RHSA-2026:22644https://access.redhat.com/errata/RHSA-2026:22963https://access.redhat.com/errata/RHSA-2026:25049https://access.redhat.com/errata/RHSA-2026:25979https://access.redhat.com/errata/RHSA-2026:28053https://access.redhat.com/errata/RHSA-2026:28054https://access.redhat.com/errata/RHSA-2026:28055https://access.redhat.com/errata/RHSA-2026:28056https://access.redhat.com/errata/RHSA-2026:28057https://access.redhat.com/errata/RHSA-2026:29863https://access.redhat.com/security/cve/CVE-2026-3012https://bugzilla.redhat.com/show_bug.cgi?id=2447319https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3012.json
2026-05-27
Published