CVE-2026-4408
published 2026-05-28CVE-2026-4408: A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password…
PriorityP268critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.75%
76.9th percentile
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
| samba | samba | — | — |
| samba | samba | >= 4.1.0 < 4.21.0 | 4.21.0 |
| ubuntu | samba | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit targets SamValidatePasswordChange and SamValidatePasswordReset RPC services on the SAMR DCE/RPC service running over NCACN_IP_TCP; monitor for unexpected or anomalous SAMR RPC calls over TCP from untrusted clients ↗
- →Shell meta-character injection arrives via the client-controlled username field passed to the 'check password script'; alert on usernames containing shell meta-characters (e.g. ;, |, $, `, &, >, <) in SAMR authentication events ↗
- →Exploitation is only possible when samba-dcerpcd is running as a system service (i.e. 'rpc start on demand helpers = no' in smb.conf); audit smb.conf for this non-default setting as a precondition indicator ↗
- →Audit smb.conf for the presence of 'check password script' containing the unquoted '%u' substitution character as a vulnerable configuration indicator ↗
- →Even with single-quoted '%u' (i.e. '%u' in smb.conf), command-line option injection remains possible; treat any use of %u in check password script as a risk ↗
- →Monitor for unexpected child processes spawned by samba-dcerpcd or smbd that are not typical Samba helper binaries, which may indicate successful RCE via the check password script ↗
- ·Vulnerability only affects Samba file servers and classic (non-AD) domain controllers; Active Directory Domain Controllers are NOT affected ↗
- ·Exploitation requires the non-default smb.conf setting 'rpc start on demand helpers = no'; in the default DCE/RPC configuration smbd starts samba-dcerpcd in a way that makes the vulnerable code inaccessible ↗
- ·Exploitation additionally requires 'check password script' to be configured with the %u substitution character in smb.conf — this is a non-standard configuration ↗
- ·No mitigation is currently available from Red Hat that meets their Product Security criteria ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.0CRITICAL
vendor_ubuntu8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2026-05-26·CVSS 8.5
CVE-2026-4480 [HIGH] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Asim Viladi Oglu Manizada discovered that Samba incorrectly handled access
checks on reparse point operations. An attacker could possibly use this
issue to modify reparse point extended attributes on files that should have
been read-only. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.
(CVE-2026-1933)
Pavel Kohout discovered that Samba's vfs_worm module did not properly block
file overwrites. An attacker could possibly use this issue to overwrite
files that should have remained immutable. (CVE-2026-2340)
Arad Inbar, Nir Somech, and Ben Grinberg discovered that Samba incorrectly
handled certificate auto-enrolment group policies over HTTP without
verification. A machine-in-the-middle attacker c
Red Hat
samba: Remote Code Execution in SAMR
vendor_redhat·2026-05-26·CVSS 9.0
CVE-2026-4408 [CRITICAL] CWE-78 samba: Remote Code Execution in SAMR
samba: Remote Code Execution in SAMR
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.
Statement: An Important remote code execution flaw exists in Samba file servers and classic domain controllers when configured with a 'check password script' that
GHSA
GHSA-jg8v-92xc-cx65: A flaw was found in Samba
ghsa_unreviewed·2026-05-28
CVE-2026-4408 [CRITICAL] CWE-78 GHSA-jg8v-92xc-cx65: A flaw was found in Samba
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-4408 samba: Remote Code Execution in SAMR [fedora-all]
bugzilla·2026-07-06·CVSS 9.8
CVE-2026-4408 [CRITICAL] CVE-2026-4408 samba: Remote Code Execution in SAMR [fedora-all]
CVE-2026-4408 samba: Remote Code Execution in SAMR [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Samba file servers and classic (non-AD) domain controllers offer the
SamValidatePasswordChange and SamValidatePasswordReset RPC services on the
SAMR DCE/RPC service when running over NCACN_IP_TCP. Both services pass a
username and password to the "check password script" that can be configured
in smb.conf.
If the "check password script" is configured with the %u
substitution character, the client-controlled username is passed to
the "check password script" without escaping shell meta-characters,
leading t
Bugzilla
CVE-2026-4408 samba: Remote Code Execution in SAMR
bugzilla·2026-05-19·CVSS 9.0
CVE-2026-4408 [CRITICAL] CVE-2026-4408 samba: Remote Code Execution in SAMR
CVE-2026-4408 samba: Remote Code Execution in SAMR
Samba file servers and classic (non-AD) domain controllers offer the
SamValidatePasswordChange and SamValidatePasswordReset RPC services on the
SAMR DCE/RPC service when running over NCACN_IP_TCP. Both services pass a
username and password to the "check password script" that can be configured
in smb.conf.
If the "check password script" is configured with the %u
substitution character, the client-controlled username is passed to
the "check password script" without escaping shell meta-characters,
leading to a remote command execution vulnerability.
This is a non-standard configuration in several ways:
It affects Samba file servers and classic (non-AD) domain controllers
that have the "check password script" configured with the %u
substit
https://access.redhat.com/errata/RHSA-2026:22644https://access.redhat.com/errata/RHSA-2026:22963https://access.redhat.com/errata/RHSA-2026:25049https://access.redhat.com/errata/RHSA-2026:25979https://access.redhat.com/errata/RHSA-2026:28053https://access.redhat.com/errata/RHSA-2026:28054https://access.redhat.com/errata/RHSA-2026:28055https://access.redhat.com/errata/RHSA-2026:28056https://access.redhat.com/errata/RHSA-2026:28057https://access.redhat.com/errata/RHSA-2026:28058https://access.redhat.com/errata/RHSA-2026:28132https://access.redhat.com/errata/RHSA-2026:29799https://access.redhat.com/errata/RHSA-2026:29833https://access.redhat.com/errata/RHSA-2026:29863https://access.redhat.com/errata/RHSA-2026:56786https://access.redhat.com/errata/RHSA-2026:56853https://access.redhat.com/errata/RHSA-2026:56911https://access.redhat.com/errata/RHSA-2026:57483https://access.redhat.com/errata/RHSA-2026:59831https://access.redhat.com/errata/RHSA-2026:60019https://access.redhat.com/errata/RHSA-2026:65839https://access.redhat.com/security/cve/CVE-2026-4408https://bugzilla.redhat.com/show_bug.cgi?id=2479762https://bugzilla.samba.org/show_bug.cgi?id=16034https://access.redhat.com/errata/RHSA-2026:22644https://access.redhat.com/errata/RHSA-2026:22963https://access.redhat.com/errata/RHSA-2026:25049https://access.redhat.com/errata/RHSA-2026:25979https://access.redhat.com/errata/RHSA-2026:28053https://access.redhat.com/errata/RHSA-2026:28054https://access.redhat.com/errata/RHSA-2026:28055https://access.redhat.com/errata/RHSA-2026:28056https://access.redhat.com/errata/RHSA-2026:28057https://access.redhat.com/errata/RHSA-2026:28058https://access.redhat.com/errata/RHSA-2026:28132https://access.redhat.com/errata/RHSA-2026:29799https://access.redhat.com/errata/RHSA-2026:29833https://access.redhat.com/errata/RHSA-2026:29863https://access.redhat.com/errata/RHSA-2026:56786https://access.redhat.com/errata/RHSA-2026:56853https://access.redhat.com/errata/RHSA-2026:56911https://access.redhat.com/errata/RHSA-2026:57483https://access.redhat.com/errata/RHSA-2026:59831https://access.redhat.com/errata/RHSA-2026:60019https://access.redhat.com/errata/RHSA-2026:65839https://access.redhat.com/security/cve/CVE-2026-4408https://bugzilla.redhat.com/show_bug.cgi?id=2479762https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4408.json
2026-05-28
Published