CVEFinder.io

CVE-2026-4408

⛔ critical
🔍 Scan for this CVE
Summary

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "che

Description

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.

CVSS Score
9.0
Critical
EPSS Score
0.8
Exploit Probability
Published Date
2026-05-28
First Seen: 2026-05-29
📊 Relative Risk Intelligence

This CVE is High Risk - more severe than 87.7% of all 326,604 vulnerabilities in our database.

#40,129
Top 25% most severe
Severity Percentile
🎯 CISA SSVC Assessment Updated: May 29, 2026
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
NO
Requires human interaction
💥 Technical Impact
Total
Complete system compromise possible
🏆 Discovered By
Red Hat would like to thank John Walker (ZeroPath) and Ron Ben Yizhak (SafeBreach) for reporting this issue.
SSVC data provided by CISA
Last Modified 2026-06-08
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE IDs (Weakness Types)

📦 Affected Products 5

🔗 References 5

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-50256 ⚠️ high 7.8 0.0 A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the... 2026-06-05
CVE-2026-50257 ⚠️ high 7.8 0.0 A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multip... 2026-06-05
CVE-2026-50258 ⚠️ high 7.8 0.0 A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers... 2026-06-05
CVE-2026-50259 ⚠️ high 7.8 0.0 A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-siz... 2026-06-05
CVE-2026-1784 ⚠️ high 8.8 0.0 The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found... 2026-06-02
CVE-2026-10533 🔶 medium 5.0 0.1 A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQ... 2026-06-01
These CVEs affect the same products