← Retour à la recherche de CVE

CVE-2026-59260

OpenWrt

Description

OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-line arguments. Attackers can pass arbitrary Samba global options such as message command to a root smbd process, triggering command execution when SMB protocol messages are processed.

CVSS 8.8EPSS 0.714%Risque 0.94
Voir la source
Publication
2026-07-12 12:16:45
Versions concernées
unknown
Type
Micrologiciel
Vecteur
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H