PT-2026-43448 · Samba+3 · Samba+3
CVE-2026-4408
·
Published
2026-05-26
·
Updated
2026-07-03
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Samba versions 4.1 through 4.23.8
Description
A flaw exists in Samba file servers and classic domain controllers that utilize the check password script feature. When this script is configured using the
%u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This allows a remote attacker to achieve remote command execution by sending a specially crafted RPC request to the DCE/RPC SAMR server module. This issue primarily affects non-standard configurations where the check password script is used with %u and the samba-dcerpcd service is running as a system service.Recommendations
Update to version 4.23.8 or later.
As a temporary workaround, avoid using the
%u substitution character in the check password script configuration or restrict the use of the check password script feature until the update is applied.Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Rocky Linux
Samba
Ubuntu