CVE Tracker

CVE-2026-4408 @ Archive

Status
new
Priority
3.85
Match score
4.0
Risk
RCE Remote priv:user
CVSS
9.0 CRITICAL
Reason
cpe: samba; pkgs: samba, samba-common, samba-common-bin, samba-dsdb-modules, samba-libs, samba-vfs-modules; version: in-range: samba-4.9.5+dfsg-5+deb10u5, samba-4.9.5+dfsg-5+deb10u5, samba-common-4.9.5+dfsg-5+deb10u5, samba-common-bin-4.9.5+dfsg-5+deb10u5, samba-dsdb-modules-4.9.5+dfsg-5+deb10u5, samba-libs-4.9.5+dfsg-5+deb10u5; risk:rce; remote
Created
2026-08-22T10:15:30Z
Updated
2026-08-22T10:15:30Z

Package interrogation (copy)

Run on the host — click to copy a command. Debian/apt

PackageCommands
samba-4.9.5+dfsg-5+deb10u5
samba-common-4.9.5+dfsg-5+deb10u5
samba-common-bin-4.9.5+dfsg-5+deb10u5
samba-dsdb-modules-4.9.5+dfsg-5+deb10u5
samba-libs-4.9.5+dfsg-5+deb10u5
samba-vfs-modules

Inventory lookup

Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.

Clear

Suggestions: samba · samba-common · samba-common-bin · samba-dsdb-modules · samba-libs · samba-vfs-modules

SystemMatchesTicket for CVE-2026-4408
Archive samba-dsdb-modules 2:4.9.5+dfsg-5+deb10u5 new open
Library samba-dsdb-modules 2:4.5.16+dfsg-1+deb9u4 new open
Saiph samba-dsdb-modules 2:4.9.5+dfsg-5+deb10u5 new open
Bullseye samba-dsdb-modules 2:4.13.13+dfsg-1~deb11u8 none
Matrix samba-dsdb-modules 2:4.17.12+dfsg-0+deb12u4 none

Same product CVEs in your queue

Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.

CVECVSSKEVSystemsStatus MatchedAlready related
CVE-2022-38023 8.1 Archive, Bullseye, Library, Saiph accepted_risk samba-common-bin
CVE-2022-37966 8.1 Archive, Bullseye, Library, Saiph accepted_risk samba-common-bin
CVE-2026-3644 7.5 Library accepted_risk samba
CVE-2026-4224 7.5 Library accepted_risk samba
CVE-2026-7210 7.5 Library accepted_risk samba → CVE-2026-15308
CVE-2026-15308 7.5 Library accepted_risk samba
CVE-2022-37967 7.2 Archive, Bullseye, Library, Saiph not_applicable samba-common-bin → CVE-2022-37966

Related CVE (same fix)

Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.

Host OS / kernel

OS
Debian GNU/Linux 10 (buster) (10) · debian
Arch
x86_64
kernel_release
uname -r → 5.10.0-25-amd64
kernel_version
uname -v → #1 SMP Debian 5.10.191-1 (2023-08-16)

For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.

Same CVE on other hosts

Open the ticket for this CVE on another system.

System Status Priority Updated
Library new 5.2 2026-08-22T10:15:30Z Open
Saiph new 3.85 2026-08-22T10:15:30Z Open

Description

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.

Update status

Also apply to other systems with this CVE:

Add note only

Also add note on:

References

NVD: CVE-2026-4408