A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J"
substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-05-26 15:16
Updated : 2026-09-01 12:17
NVD link : CVE-2026-4480
Mitre link : CVE-2026-4480
CVE.ORG link : CVE-2026-4480
JSON object : View
Products Affected
redhat
- enterprise_linux
- openshift_container_platform
samba
- samba
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
