← العودة للجدول
CVE-2026-4408
CVE-2026-4408 — A flaw was found in Samba. A remote attacker can exploit a misconfiguration in S
📅 2026-05-28
🔴 Critical 🔥 No NVD Exploit Exploit CVSS 9 🎯 EPSS 0.23%

📋 الوصف الكامل

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote com

💻 الأنظمة المتأثرة

A flaw was

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-4408

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2026-4408 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←