A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.
The vulnerability results from improper escaping of shell meta-characters during substitution of the client-controlled username using the %u specifier in the 'check password script' configuration option. An attacker can craft a malicious username containing shell meta-characters, which will be passed directly to the executed script without sanitization. The exploit is effective only in non-standard configurations where the 'check password script' option with %u substitution is active and the samba-dcerpcd service is running as a system service.
A remote, unauthenticated attacker can gain the ability to execute arbitrary system commands on the vulnerable server, leading to breach of confidentiality, integrity, and availability of the system — potentially resulting in complete server compromise.
Apply patches available from the vendor according to the references (Samba Bugzilla #16034, Red Hat Security Advisory CVE-2026-4408). Until updates are applied, it is recommended to remove the %u substitution from the 'check password script' configuration or disable this feature if not required, as well as restrict or stop the samba-dcerpcd service as a system service where not essential.
Samba configured as a file server or classic domain controller with the active 'check password script' option containing %u substitution and the samba-dcerpcd service running as a system service. Specific product versions are indicated in the vendor's references.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HRed Hat Enterprise Linux
OSRedhat6.07.09.0Red Hat OpenShift Container Platform
APPRedhat4.0Samba
APPSamba4.1.0 – 4.21.0 (excl.)
Related vulnerabilities
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
RCE w Kibana Timelion — wykonanie kodu z uprawnieniami procesu
Jenkins Script Security Plugin — sandbox bypass umożliwiający RCE
Jenkins Pipeline Groovy Plugin — bypass sandbox i wykonanie kodu (RCE)