{"id":"AZL-88883","summary":"CVE-2026-4408 affecting package samba 4.18.3-2","details":"A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the \"check password script\" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the \"check password script\" is used with %u and the samba-dcerpcd service is started as a system service.","modified":"2026-08-30T05:24:52Z","published":"2026-05-28T09:16:47Z","upstream":["CVE-2026-4408"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4408"}],"affected":[{"package":{"name":"samba","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/samba"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"4.18.3-2"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-88883.json"}}],"schema_version":"1.9.0"}