


Perceptive Security
SOC/SIEM Consultancy

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password sc…
Published:
27 May 2026 at 22:00:00
Alert date:
28 May 2026 at 10:00:55
Source:
nvd.nist.gov
Network Infrastructure, Enterprise Applications
A critical vulnerability was discovered in Samba file servers and domain controllers that use the 'check password script' feature with %u substitution. Remote attackers can exploit improper escaping of shell meta-characters in client-controlled usernames to achieve remote command execution. The vulnerability primarily affects non-standard configurations where the check password script uses %u and samba-dcerpcd runs as a system service. This represents a significant security risk for affected Samba deployments.
Technical details
Mitigation steps:
Affected products:
Samba
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-4408
https://access.redhat.com/security/cve/CVE-2026-4408
https://bugzilla.redhat.com/show_bug.cgi?id=2479762
https://bugzilla.samba.org/show_bug.cgi?id=16034
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
