← العودة للجدول
CVE-2026-49818
CVE-2026-49818 — The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object
📅 2026-06-09
🟠 High 🔥 No NVD Exploit Windows

📋 الوصف الكامل

The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an object named with `../` segments resolved a write path outside the configured `destination_path`. An attacker able to write objects into the source GCS bucket — typically an external data producer distinct from the trusted DAG author — could write

💻 الأنظمة المتأثرة

Apache HTTP Server

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-49818

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2026-49818 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←