Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4110 articles · 197511 vulns · 37/41 feeds (7d)
← Back to list
8.0
CVE-2026-3012PATCHED
red hat · red hat enterprise linux

Samba: group policy certificate enrollment uses http:// without validation

Description

A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.

Affected Products

VendorProductVersions
red hatred hat enterprise linux—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
canonicalubuntu linuxcert_advisory90%
debiandebian linuxcert_advisory90%
open sourcesambacert_advisory90%
sususe linuxcert_advisory90%

References

  • https://access.redhat.com/errata/RHSA-2026:22644(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:22963(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:25049(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:25979(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28053(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28054(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28055(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28056(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28057(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:29863(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/security/cve/CVE-2026-3012(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2447319(issue-tracking, x_refsource_REDHAT)
  • https://bugzilla.samba.org/show_bug.cgi?id=16003

Related News (5 articles)

Tier B
CERT-FR19d ago
Multiples vulnérabilités dans les produits IBM (07 août 2026)
→ No new info (linked only)
Tier C
VulDB90d ago
CVE-2026-3012 | Samba Group Policy data authenticity
→ No new info (linked only)
Tier B
BSI Advisories90d ago
[NEU] [hoch] Samba: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
oss-security90d ago
Samba 4.24.3, 4.23.8 and 4.22.10 Security Releases are available for Download
→ No new info (linked only)
Tier B
CERT-FR91d ago
Multiples vulnérabilités dans Samba (27 mai 2026)
→ No new info (linked only)
CVSS 3.18.0 NONE
CISA KEV❌ No
Actively exploited❌ No
Patch available
0:4.19.4-16.el8_10
CWECWE-345
PublishedMay 27, 2026
Last enriched90d agov2
Trending Score6
Source articles5
Independent4
Info Completeness6/14
Missing: versions, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-78367EXP
Rpm: rpmbuild gettarspec() crafted tar member name → macro injection
Trending: 59
NONECVE-2026-78465EXP
Gimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bit
Trending: 59
HIGHCVE-2026-79655EXP
Sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/hardlink targets leads to arbitrary file write
Trending: 56
NONECVE-2026-18963
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
Trending: 54
CRITICALCVE-2026-19685EXP
Networkmanager: networkmanager: 802-1x ca-path and phase2-ca-path bypass private_user restriction, allowing wpa-enterprise server validation bypass (incomplete fix for cve-2025-9615)
Trending: 54

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 27, 2026
Discovered by ZDM
May 27, 2026
Updated: description, severity
May 27, 2026
Patch Available
Aug 21, 2026

Version History

v2
Last enriched 90d ago
v2Tier C90d ago

Updated vendor to Samba, product to Group Policy Handler, severity to MEDIUM, and noted that no exploit is available.

descriptionseverity
via VulDB
v190d ago

Initial creation