Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5049 articles · 189092 vulns · 37/41 feeds (7d)
← Back to list
8.5
CVE-2026-4480KEVEXPLOITEDPATCHED
red hat · openshift_container_platform

Samba: samba: remote code execution in printing subsystem via unescaped job description

Description

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.

Affected Products

VendorProductVersions
red hatopenshift_container_platform—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
canonicalubuntu linuxcert_advisory90%
debiandebian linuxcert_advisory90%
open sourcesambacert_advisory90%
red hatenterprise_linuxcve_cpe95%
sambasambacve_cpe95%

References

  • https://access.redhat.com/errata/RHSA-2026:22644(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:22963(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:25049(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:25979(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28053(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28054(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28055(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28056(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28057(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28058(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:28132(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/security/cve/CVE-2026-4480(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2452232(issue-tracking, x_refsource_REDHAT)
  • https://bugzilla.samba.org/show_bug.cgi?id=16033

Related News (5 articles)

Tier B
CERT-FR5d ago
Multiples vulnérabilités dans les produits IBM (07 août 2026)
→ No new info (linked only)
Tier B
CERT-FR72d ago
Bulletin d'actualité CERTFR-2026-ACT-024 (01 juin 2026)
→ No new info (linked only)
Tier B
BSI Advisories77d ago
[NEU] [hoch] Samba: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR77d ago
Multiples vulnérabilités dans Samba (27 mai 2026)
→ No new info (linked only)
Tier C
VulDB78d ago
CVE-2026-4480 | Samba Print Command os command injection
→ No new info (linked only)
CVSS 3.18.5 NONE
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
0:4.19.4-16.el8_10
CWECWE-78
PublishedMay 26, 2026
Last enriched78d agov2
Trending Score48
Source articles5
Independent3
Info Completeness6/14
Missing: versions, cvss, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-59091EXP
Gimp: gimp: multiple vulnerabilities in file format plugins via crafted image file
Trending: 46
MEDIUMCVE-2026-6426EXP
Qemu-kvm: vhost inflight migration vmstate integer type mismatch causes out-of-bounds access
Trending: 45
NONECVE-2026-59090EXP
Gimp: gimp: arbitrary code execution in psd plugin due to unsigned underflow
Trending: 44
LOWCVE-2026-61477EXP
Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injection
Trending: 43
NONECVE-2026-63623EXP
Libvirt: information disclosure via world-readable storage volume images during clone/convert
Trending: 42

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 26, 2026
Added to CISA KEV
May 26, 2026
Discovered by ZDM
May 26, 2026
Updated: description, severity, activelyExploited
May 26, 2026
Actively Exploited
Jun 23, 2026
Patch Available
Jun 23, 2026

Version History

v2
Last enriched 78d ago
v2Tier C78d ago

Updated description with critical vulnerability details, changed vendor and product to 'samba', updated severity to CRITICAL, and noted that there is no exploit available.

descriptionseverityactivelyExploited
via VulDB
v178d ago

Initial creation