Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-4408

Опубликовано: 28 мая 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 9

Описание

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.

РелизСтатусПримечание
devel

not-affected

2:4.23.6+dfsg-1ubuntu3
esm-infra-legacy/trusty

ignored

changes too intrusive
esm-infra-legacy/xenial

ignored

changes too intrusive
esm-infra/bionic

ignored

changes too intrusive
esm-infra/focal

released

2:4.15.13+dfsg-0ubuntu0.20.04.8+esm2
esm-infra/xenial

ignored

end of ESM support, was needs-triage
jammy

released

2:4.15.13+dfsg-0ubuntu1.12
noble

released

2:4.19.5+dfsg-4ubuntu9.6
questing

released

2:4.22.3+dfsg-4ubuntu2.4
resolute

released

2:4.23.6+dfsg-1ubuntu2.1

Показывать по

EPSS

Процентиль: 83%
0.02501
Низкий

9 Critical

CVSS3

Связанные уязвимости

CVSS3: 9
redhat
2 месяца назад

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.

CVSS3: 9
nvd
2 месяца назад

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.

CVSS3: 9
debian
2 месяца назад

A flaw was found in Samba. A remote attacker can exploit a misconfigur ...

CVSS3: 9
github
2 месяца назад

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.

CVSS3: 10
fstec
2 месяца назад

Уязвимость функции check password script модуля DCE/RPC SAMR server пакета программ сетевого взаимодействия Samba, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 83%
0.02501
Низкий

9 Critical

CVSS3