CVE-2026-4408
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://access.redhat.com/downloads/content/package-browser/, https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4408.json, https://access.redhat.com/errata/RHSA-2026:22644, https://access.redhat.com/errata/RHSA-2026:22963, https://access.redhat.com/errata/RHSA-2026:25049, https://access.redhat.com/errata/RHSA-2026:25979, https://access.redhat.com/errata/RHSA-2026:28053, https://access.redhat.com/errata/RHSA-2026:28054, https://access.redhat.com/errata/RHSA-2026:28055, https://access.redhat.com/errata/RHSA-2026:28056, https://access.redhat.com/errata/RHSA-2026:28057, https://access.redhat.com/errata/RHSA-2026:28058, https://access.redhat.com/errata/RHSA-2026:28132, https://access.redhat.com/errata/RHSA-2026:29799, https://access.redhat.com/errata/RHSA-2026:29833, https://access.redhat.com/errata/RHSA-2026:29863, https://access.redhat.com/security/cve/CVE-2026-4408, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4408.json, https://nvd.nist.gov/vuln/detail/CVE-2026-4408, https://bugzilla.redhat.com/showbug.cgi?id=2479762, https://bugzilla.samba.org/showbug.cgi?id=16034