Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-07422

Опубликовано: 26 мая 2026
Источник: fstec
CVSS3: 8
CVSS2: 6.2
EPSS Низкий

Описание

Уязвимость компонента управления групповыми политиками (GPO) программного обеспечения Samba связана с недостаточной проверкой подлинности данных. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, обойти существующие ограничения безопасности

Вендор

Red Hat Inc.
Сообщество свободного программного обеспечения
Amazon.com Inc.
Canonical Ltd.
Samba Team

Наименование ПО

Red Hat Enterprise Linux
OpenShift Container Platform
Debian GNU/Linux
Amazon Linux
Ubuntu
Samba

Версия ПО

7 (Red Hat Enterprise Linux)
8 (Red Hat Enterprise Linux)
4 (OpenShift Container Platform)
12 (Debian GNU/Linux)
9 (Red Hat Enterprise Linux)
2023 (Amazon Linux)
24.04 LTS (Ubuntu)
10 (Red Hat Enterprise Linux)
13 (Debian GNU/Linux)
25.10 (Ubuntu)
26.04 LTS (Ubuntu)
от 4.16 до 4.22.10 (Samba)
от 4.16 до 4.23.8 (Samba)
от 4.16 до 4.24.3 (Samba)

Тип ПО

Операционная система
Прикладное ПО информационных систем
Сетевое программное средство

Операционные системы и аппаратные платформы

Red Hat Inc. Red Hat Enterprise Linux 7
Red Hat Inc. Red Hat Enterprise Linux 8
Сообщество свободного программного обеспечения Debian GNU/Linux 12
Red Hat Inc. Red Hat Enterprise Linux 9
Amazon.com Inc. Amazon Linux 2023
Canonical Ltd. Ubuntu 24.04 LTS
Red Hat Inc. Red Hat Enterprise Linux 10
Сообщество свободного программного обеспечения Debian GNU/Linux 13
Canonical Ltd. Ubuntu 25.10
Canonical Ltd. Ubuntu 26.04 LTS

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 6,2)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 8)

Возможные меры по устранению уязвимости

Использование рекомендаций:
Для Samba:
https://www.samba.org/samba/security/CVE-2026-3012.html
Для Amazon Linux:
https://explore.alas.aws.amazon.com/CVE-2026-3012.html
Для Ubuntu:
https://ubuntu.com/security/notices/USN-8306-1
Для Debian GNU/Linux:
https://security-tracker.debian.org/tracker/DSA-6297-1
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-3012
Компенсирующие меры:
- исключить инициализацию уязвимого исполняемого кода путем перевода параметра apply group policies в состояние "no" или удаления соответствующей строки в конфигурационном файле smb.conf;
- отключить автоматическую регистрацию сертификатов с помощью редактора управления групповыми политиками Windows (GPME);
- обеспечить изоляцию локальной сети для предотвращения перехвата HTTP-запросов или перенаправления трафика

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Существует в открытом доступе

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 18%
0.00261
Низкий

8 High

CVSS3

6.2 Medium

CVSS2

Связанные уязвимости

CVSS3: 8
ubuntu
2 месяца назад

A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.

CVSS3: 8
redhat
2 месяца назад

A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.

CVSS3: 8
nvd
2 месяца назад

A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.

CVSS3: 8
debian
2 месяца назад

A flaw was found in Samba\u2019s certificate auto-enrollment Group Pol ...

CVSS3: 8
github
2 месяца назад

A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.

EPSS

Процентиль: 18%
0.00261
Низкий

8 High

CVSS3

6.2 Medium

CVSS2