PT-2026-43448 · Samba+3 · Samba+3

CVE-2026-4408

·

Published

2026-05-26

·

Updated

2026-07-03

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Samba versions 4.1 through 4.23.8
Description A flaw exists in Samba file servers and classic domain controllers that utilize the check password script feature. When this script is configured using the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This allows a remote attacker to achieve remote command execution by sending a specially crafted RPC request to the DCE/RPC SAMR server module. This issue primarily affects non-standard configurations where the check password script is used with %u and the samba-dcerpcd service is running as a system service.
Recommendations Update to version 4.23.8 or later. As a temporary workaround, avoid using the %u substitution character in the check password script configuration or restrict the use of the check password script feature until the update is applied.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:22644
ALSA-2026:22963
ALSA-2026:25049
BDU:2026-07316
CVE-2026-4408
ECHO-E406-9590-08F0
OESA-2026-2574
OESA-2026-2575
OESA-2026-2576
OESA-2026-2577
OPENSUSE-SU-2026:10884-1
OPENSUSE-SU-2026:20905-1
RHSA-2026:22963
RHSA-2026:25049
RHSA-2026:28058
RHSA-2026:28132
SUSE-SU-2026:2071-1
SUSE-SU-2026:2072-1
SUSE-SU-2026:2073-1
SUSE-SU-2026:2074-1
SUSE-SU-2026:2076-1
SUSE-SU-2026:2108-1
SUSE-SU-2026:22045-1
SUSE-SU-2026:22080-1
USN-8306-1
USN-8306-2

Affected Products

Linuxmint
Rocky Linux
Samba
Ubuntu