Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58221

Опубликовано: 28 июл. 2026
Источник: redhat
CVSS3: 8.8

Описание

A flaw was found in Samba Active Directory Domain Controller (AD DC). Improper authorization checks allow an authenticated low-privilege domain user to modify internal LDB special records through LDAP. By altering the DSDB module configuration, an attacker can bypass directory ACL enforcement on new LDAP connections and elevate privileges, potentially leading to complete domain compromise.

Отчет

Red Hat Product Security has rated this vulnerability as having an Important security impact for Samba deployments operating as an Active Directory Domain Controller (AD DC).

Red Hat Enterprise Linux (RHEL) context: Standard installations of Red Hat Enterprise Linux (RHEL) are not affected. RHEL packages Samba strictly to operate as a file server (smbd), print server, or Active Directory domain member (winbindd). RHEL does not ship or support the Samba Active Directory Domain Controller (AD DC) role where this internal LDB filtering flaw exists.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10sambaNot affected
Red Hat Enterprise Linux 6sambaNot affected
Red Hat Enterprise Linux 6samba4Not affected
Red Hat Enterprise Linux 7sambaNot affected
Red Hat Enterprise Linux 8sambaNot affected
Red Hat Enterprise Linux 9sambaNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=2502726samba: authenticated LDAP access to internal LDB special DNs permits domain takeover

8.8 High

CVSS3

Связанные уязвимости

ubuntu
7 дней назад

Samba AD authenticated LDAP access domain takeover. Samba AD low-privilege authenticated LDAP access allows modifications to internal LDB special DNs, which permits a domain takeover.

debian

[Samba AD authenticated LDAP access domain takeover]

suse-cvrf
6 дней назад

Security update for samba

suse-cvrf
7 дней назад

Security update for samba

suse-cvrf
7 дней назад

Security update for samba

8.8 High

CVSS3

Уязвимость CVE-2026-58221