cbcvebase.
CVE-2026-4408
published 2026-05-28

CVE-2026-4408: A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password…

PriorityP268critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.75%
76.9th percentile
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.

Affected

7 ranges
VendorProductVersion rangeFixed in
redhatenterprise_linux——
redhatenterprise_linux——
redhatenterprise_linux——
redhatopenshift_container_platform——
sambasamba——
sambasamba>= 4.1.0 < 4.21.04.21.0
ubuntusamba——

Detection & IOCsextracted from sources · hover to see the quote

  • →Exploit targets SamValidatePasswordChange and SamValidatePasswordReset RPC services on the SAMR DCE/RPC service running over NCACN_IP_TCP; monitor for unexpected or anomalous SAMR RPC calls over TCP from untrusted clients ↗
  • →Shell meta-character injection arrives via the client-controlled username field passed to the 'check password script'; alert on usernames containing shell meta-characters (e.g. ;, |, $, `, &, >, <) in SAMR authentication events ↗
  • →Exploitation is only possible when samba-dcerpcd is running as a system service (i.e. 'rpc start on demand helpers = no' in smb.conf); audit smb.conf for this non-default setting as a precondition indicator ↗
  • →Audit smb.conf for the presence of 'check password script' containing the unquoted '%u' substitution character as a vulnerable configuration indicator ↗
  • →Even with single-quoted '%u' (i.e. '%u' in smb.conf), command-line option injection remains possible; treat any use of %u in check password script as a risk ↗
  • →Monitor for unexpected child processes spawned by samba-dcerpcd or smbd that are not typical Samba helper binaries, which may indicate successful RCE via the check password script ↗
  • ·Vulnerability only affects Samba file servers and classic (non-AD) domain controllers; Active Directory Domain Controllers are NOT affected ↗
  • ·Exploitation requires the non-default smb.conf setting 'rpc start on demand helpers = no'; in the default DCE/RPC configuration smbd starts samba-dcerpcd in a way that makes the vulnerable code inaccessible ↗
  • ·Exploitation additionally requires 'check password script' to be configured with the %u substitution character in smb.conf — this is a non-standard configuration ↗
  • ·No mitigation is currently available from Red Hat that meets their Product Security criteria ↗

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.0CRITICAL
vendor_ubuntu8.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.