Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3435 articles · 210641 vulns · 37/41 feeds (7d)
← Back to list
8.5
CVE-2026-4480KEVEXPLOITEDPATCHED
red hat · openshift_container_platform

Samba: samba: remote code execution in printing subsystem via unescaped job description

Description

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.

Affected Products

VendorProductVersions
red hatopenshift_container_platform—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
canonicalubuntu linuxcert_advisory90%
debiandebian linuxcert_advisory90%
open sourcesambacert_advisory90%
red hatenterprise_linuxcve_cpe95%
sambasambacve_cpe95%

References

  • https://access.redhat.com/errata/RHSA-2026:22644(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:22963(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:25049(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:25979(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28053(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28054(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28055(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28056(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28057(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28058(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28132(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/security/cve/CVE-2026-4480(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2452232(issue-tracking, x_refsource_REDHAT)
  • https://bugzilla.samba.org/show_bug.cgi?id=16033

Related News (5 articles)

Tier B
CERT-FR30d ago
Multiples vulnérabilités dans les produits IBM (07 août 2026)
→ No new info (linked only)
Tier B
CERT-FR97d ago
Bulletin d'actualité CERTFR-2026-ACT-024 (01 juin 2026)
→ No new info (linked only)
Tier B
BSI Advisories101d ago
[NEU] [hoch] Samba: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR102d ago
Multiples vulnérabilités dans Samba (27 mai 2026)
→ No new info (linked only)
Tier C
VulDB102d ago
CVE-2026-4480 | Samba Print Command os command injection
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.5 NONE
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
0:4.19.4-16.el8_10
CWECWE-78
PublishedMay 26, 2026
Last enriched102d agov2
Trending Score2
Source articles5
Independent3
Info Completeness6/14
Missing: versions, cvss, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-18963
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
Trending: 37
HIGHCVE-2026-85150EXP
Gstreamer1-plugins-base: gstreamer: null/invalid-pointer dereference in gst_rtsp_message_parse_auth_credentials() when parsing a crafted digest authorization/www-authenticate header
Trending: 37
NONECVE-2026-81665EXP
Corosync: corosync: heap-based buffer overflow in totempg assembly buffer during fragmented message reassembly
Trending: 36
NONECVE-2026-85534EXP
Libsoup: libsoup: http/2 client crash in on_data_source_read_callback when settings initial_window_size shrinks during deferred body read
Trending: 32
NONECVE-2026-78409
Util-linux: util-linux: x-mount.subdir detached-tree resolution can escape via intermediate symlinks
Trending: 31

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 26, 2026
Added to CISA KEV
May 26, 2026
Discovered by ZDM
May 26, 2026
Updated: description, severity, activelyExploited
May 26, 2026
Actively Exploited
Sep 1, 2026
Patch Available
Sep 1, 2026

Version History

v2
Last enriched 102d ago
v2Tier C102d ago

Updated description with critical vulnerability details, changed vendor and product to 'samba', updated severity to CRITICAL, and noted that there is no exploit available.

descriptionseverityactivelyExploited
via VulDB
v1102d ago

Initial creation