Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4110 articles · 197511 vulns · 37/41 feeds (7d)
← Back to list
9.0
CVE-2026-4408PATCHED
red hat · red hat enterprise linux

Samba: remote code execution in samr

Description

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.

Affected Products

VendorProductVersions
red hatred hat enterprise linux—

References

  • https://access.redhat.com/errata/RHSA-2026:22644(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:22963(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:25049(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:25979(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28053(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28054(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28055(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28056(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28057(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28058(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28132(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:29799(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:29833(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:29863(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/security/cve/CVE-2026-4408(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2479762(issue-tracking, x_refsource_REDHAT)
  • https://bugzilla.samba.org/show_bug.cgi?id=16034

Related News (6 articles)

Tier B
CERT-FR19d ago
Multiples vulnérabilités dans les produits IBM (07 août 2026)
→ No new info (linked only)
Tier B
CERT-FR86d ago
Bulletin d'actualité CERTFR-2026-ACT-024 (01 juin 2026)
→ No new info (linked only)
Tier C
VulDB89d ago
CVE-2026-4408 | Samba samba-dcerpcd Service os command injection
→ No new info (linked only)
Tier B
BSI Advisories90d ago
[NEU] [hoch] Samba: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
oss-security90d ago
Samba 4.24.3, 4.23.8 and 4.22.10 Security Releases are available for Download
→ No new info (linked only)
Tier B
CERT-FR91d ago
Multiples vulnérabilités dans Samba (27 mai 2026)
→ No new info (linked only)
CVSS 3.19.0 NONE
CISA KEV❌ No
Actively exploited❌ No
Patch available
0:4.19.4-16.el8_10
CWECWE-78
PublishedMay 28, 2026
Last enriched89d agov2
Trending Score6
Source articles6
Independent4
Info Completeness7/14
Missing: versions, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-78367EXP
Rpm: rpmbuild gettarspec() crafted tar member name → macro injection
Trending: 59
NONECVE-2026-78465EXP
Gimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bit
Trending: 59
HIGHCVE-2026-79655EXP
Sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/hardlink targets leads to arbitrary file write
Trending: 56
NONECVE-2026-18963
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
Trending: 54
CRITICALCVE-2026-19685EXP
Networkmanager: networkmanager: 802-1x ca-path and phase2-ca-path bypass private_user restriction, allowing wpa-enterprise server validation bypass (incomplete fix for cve-2025-9615)
Trending: 54

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 28, 2026
Discovered by ZDM
May 28, 2026
Updated: description
May 28, 2026
Patch Available
Aug 25, 2026

Version History

v2
Last enriched 89d ago
v2Tier C89d ago

Updated description with new details about the vulnerability and corrected vendor and product information.

description
via VulDB
v189d ago

Initial creation