{"id":"AZL-88880","summary":"CVE-2026-4480 affecting package samba 4.18.3-2","details":"A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the \"print command\" setting via the \"%J\"\nsubstitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.","modified":"2026-08-30T05:24:52Z","published":"2026-05-26T15:16:40Z","upstream":["CVE-2026-4480"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4480"}],"affected":[{"package":{"name":"samba","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/samba"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"4.18.3-2"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-88880.json"}}],"schema_version":"1.9.0"}