SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-25706

HIGH · CVSS 7.5 EPSS 0.44%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The yast2-samba-client is vulnerable due to improper handling of special elements in OS commands, allowing an attacker with control over an Active Directory directory tree to execute arbitrary commands as root on affected systems. This vulnerability poses a significant risk, particularly for organizations using Samba to integrate with Active Directory, as it could lead to unauthorized access and system compromise. Organizations utilizing yast2-samba-client versions up to 5.0.4 should prioritize patching this vulnerability to mitigate potential exploitation.

CVE
CVE-2026-25706
Severity
HIGH
CVSS
7.5
EPSS
0.44%

Original NVD Description

Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who controls the content of an Active Directory directory tree - a rogue domain controller, or a directory user delegated the right to create objects - to execute arbitrary commands as root on a machine being joined to that domain. This issue affects yast2-samba-client through 5.0.4.