CVE-2026-4480
published 2026-05-26CVE-2026-4480: A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command"…
PriorityP184critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
12.80%
95.8th percentile
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J"
substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
| samba | samba | — | — |
| samba | samba | >= 4.1.0 < 4.2.1 | 4.2.1 |
| ubuntu | samba | — | — |
Detection & IOCsextracted from sources · hover to see the quote
sigma↗
compare_versions(version, '= 4.23.0', '= 4.24.0', '< 4.24.3')
yara↗
regex: Samba ([0-9]+\.[0-9]+\.[0-9]+[a-z]*)
- →Monitor Samba print job submissions containing unescaped shell metacharacters in the job description field, particularly when the smb.conf 'print command' setting includes the '%J' substitution parameter. ↗
- →Scan Samba banners on port 445 to identify vulnerable versions (4.23.0, 4.24.0–4.24.2) using SMB info-mode enumeration; match banner string 'Samba' and extract version. ↗
- →Reference upstream Samba bug tracker entry 16033 for technical details and patch diffs useful for building detection signatures. ↗
- ·Red Hat assesses attack complexity as High (AC:H) and Privileges Required as Low (PR:L) for typical RHEL deployments, diverging from the NVD CVSS 9.8 score, because exploitation depends on non-default configurations and authenticated access is typically required. ↗
- ·The Nuclei template targets Samba versions 4.23.0, 4.24.0, and < 4.24.3 as vulnerable; fixed versions are 4.22.10, 4.23.8, and 4.24.3 or later. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.5HIGH
vendor_ubuntu8.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2026-05-26·CVSS 8.5
CVE-2026-4480 [HIGH] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Asim Viladi Oglu Manizada discovered that Samba incorrectly handled access
checks on reparse point operations. An attacker could possibly use this
issue to modify reparse point extended attributes on files that should have
been read-only. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.
(CVE-2026-1933)
Pavel Kohout discovered that Samba's vfs_worm module did not properly block
file overwrites. An attacker could possibly use this issue to overwrite
files that should have remained immutable. (CVE-2026-2340)
Arad Inbar, Nir Somech, and Ben Grinberg discovered that Samba incorrectly
handled certificate auto-enrolment group policies over HTTP without
verification. A machine-in-the-middle attacker c
Red Hat
samba: Samba: Remote Code Execution in printing subsystem via unescaped job description
vendor_redhat·2026-05-26·CVSS 8.5
CVE-2026-4480 [HIGH] CWE-78 samba: Samba: Remote Code Execution in printing subsystem via unescaped job description
samba: Samba: Remote Code Execution in printing subsystem via unescaped job description
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J"
substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.
Statement: The issue affects the Samba printing subsystem. Red Hat has classified this issue as Important severity rather than Critical.
Print servers configured with ```"printing = cups"``` or ```"printing = iprint"```, and print servers that do not have
GHSA
GHSA-hwwh-4hhw-h9jf: A flaw was found in the Samba printing subsystem
ghsa_unreviewed·2026-05-26
CVE-2026-4480 [HIGH] CWE-78 GHSA-hwwh-4hhw-h9jf: A flaw was found in the Samba printing subsystem
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J"
substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.
No detection rules found.
Nuclei
Samba Printing Subsystem - Remote Code Execution
nuclei·CVSS 9.8
CVE-2026-4480 [CRITICAL] Samba Printing Subsystem - Remote Code Execution
Samba Printing Subsystem - Remote Code Execution
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.
Template:
id: CVE-2026-4480
info:
name: Samba Printing Subsystem - Remote Code Execution
author: projectdiscovery
severity: critical
description: |
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "p
Bugzilla
CVE-2026-4480 samba: Samba: Remote Code Execution in printing subsystem via unescaped job description [fedora-all]
bugzilla·2026-05-26·CVSS 8.5
CVE-2026-4480 [HIGH] CVE-2026-4480 samba: Samba: Remote Code Execution in printing subsystem via unescaped job description [fedora-all]
CVE-2026-4480 samba: Samba: Remote Code Execution in printing subsystem via unescaped job description [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-4480 samba: Samba: Remote Code Execution in printing subsystem via unescaped job description
bugzilla·2026-03-27·CVSS 8.5
CVE-2026-4480 [HIGH] CVE-2026-4480 samba: Samba: Remote Code Execution in printing subsystem via unescaped job description
CVE-2026-4480 samba: Samba: Remote Code Execution in printing subsystem via unescaped job description
Samba: Unauthenticated Remote Code Execution in Samba printing subsystem
Discussion:
Lifting Embargo. The CVE is now public - https://bugzilla.samba.org/show_bug.cgi?id=16033
Hackernews
⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More
blogs_hackernews·2026-06-01·CVSS 7.8
CVE-2026-0257 [HIGH] ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More
Monday hit like a cron job with anger issues.
A busted auth path here, a repo-side faceplant there, some "patched-ish" thing already getting chewed on in the wild, and then the usual bonus round: poisoned dev tools, sketchy forum chatter, phishing kits pretending to be productivity, and AI lowering the bar for people who already thought 'curl | sh' had a personality.
The vibe is simple: old bugs, new wrappers, faster abuse. Patch the obvious crap first. Then read the rest.
## ⚡ Threat of the Week
PAN-OS GlobalProtect Authenticati
Wiz
CVE-2025-20805 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.7
CVE-2025-20805 [MEDIUM] CVE-2025-20805 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-20805 :
NixOS vulnerability analysis and mitigation
In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10114696; Issue ID: MSV-4480.
Source : NVD
## 6.7
Score
Published January 6, 2026
Severity MEDIUM
CNA Score 6.7
Affected Technologies
NixOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
android
Sources
NVD
Nix Severity MEDIUM No Fix Added at: Jan 12, 2026
## Get a CVE risk assessment
Get a prioritize
https://access.redhat.com/errata/RHSA-2026:22644https://access.redhat.com/errata/RHSA-2026:22963https://access.redhat.com/errata/RHSA-2026:25049https://access.redhat.com/errata/RHSA-2026:25979https://access.redhat.com/errata/RHSA-2026:28053https://access.redhat.com/errata/RHSA-2026:28054https://access.redhat.com/errata/RHSA-2026:28055https://access.redhat.com/errata/RHSA-2026:28056https://access.redhat.com/errata/RHSA-2026:28057https://access.redhat.com/errata/RHSA-2026:28058https://access.redhat.com/errata/RHSA-2026:28132https://access.redhat.com/security/cve/CVE-2026-4480https://bugzilla.redhat.com/show_bug.cgi?id=2452232https://bugzilla.samba.org/show_bug.cgi?id=16033https://access.redhat.com/errata/RHSA-2026:22644https://access.redhat.com/errata/RHSA-2026:22963https://access.redhat.com/errata/RHSA-2026:25049https://access.redhat.com/errata/RHSA-2026:25979https://access.redhat.com/errata/RHSA-2026:28053https://access.redhat.com/errata/RHSA-2026:28054https://access.redhat.com/errata/RHSA-2026:28055https://access.redhat.com/errata/RHSA-2026:28056https://access.redhat.com/errata/RHSA-2026:28057https://access.redhat.com/errata/RHSA-2026:28058https://access.redhat.com/errata/RHSA-2026:28132https://access.redhat.com/security/cve/CVE-2026-4480https://bugzilla.redhat.com/show_bug.cgi?id=2452232https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4480.json
2026-05-26
Published