


Perceptive Security
SOC/SIEM Consultancy

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password sc…
Published:
27 May 2026 at 22:00:00
Alert date:
28 May 2026 at 14:02:15
Source:
nvd.nist.gov
Operating Systems, Network Infrastructure, Identity & Access
A critical vulnerability in Samba file servers and domain controllers allows remote attackers to achieve command execution through improper escaping of shell meta-characters in the 'check password script' feature. The flaw occurs when the script is configured with the %u substitution character, allowing client-controlled usernames to be passed without proper sanitization. This primarily affects non-standard configurations where the check password script uses %u and the samba-dcerpcd service runs as a system service. The vulnerability enables remote code execution on affected systems through exploitation of the misconfigured password checking mechanism.
Technical details
Mitigation steps:
Affected products:
Samba
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-4408
https://access.redhat.com/security/cve/CVE-2026-4408
https://bugzilla.redhat.com/show_bug.cgi?id=2479762
https://bugzilla.samba.org/show_bug.cgi?id=16034
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
