---
schema: 1
kind: vulnerability
title: "CVE-2026-4408 & CVE-2026-4480 — Samba: unauthenticated RCE in SAMR RPC and print-command subsystems (CVSS 10.0)"
headline: "CVE-2026-4408 & CVE-2026-4480 — Samba: unauthenticated RCE in SAMR RPC and print-command subsystems (CVSS 10.0)"
summary: "Samba ships 4.22.10 / 4.23.8 / 4.24.3 closing two unauthenticated RCEs at CVSS 10.0 — CVE-2026-4408 (SAMR %u shell injection) and CVE-2026-4480 (print-command %J shell injection). AD DCs unaffected; classic-printing and on-demand DCERPC SAMR file-server roles are."
discovered_at: "2026-05-29T05:00:06Z"
event_date: 2026-05-27
run_id: 2026-05-29-c7f56b00
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - pre-auth
  - patch-available
regions:
  - global
  - europe
  - switzerland
sectors:
  - public-sector
  - education
  - healthcare
entities: []
cves:
  - id: CVE-2026-4408
    cvss: "10.0"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-4480
    cvss: "10.0"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
sources:
  - url: "https://www.samba.org/samba/security/CVE-2026-4408.html"
    publisher: Samba Project CVE-2026-4408
    role: primary
  - url: "https://www.samba.org/samba/security/CVE-2026-4480.html"
    publisher: Samba Project CVE-2026-4480
    role: corroborating
  - url: "https://www.openwall.com/lists/oss-security/2026/05/27/6"
    publisher: oss-security
    role: corroborating
  - url: "https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0651/"
    publisher: CERT-FR CERTFR-2026-AVI-0651
    role: corroborating
closed_sources: []
evidence:
  - quote: "the client-controlled username is passed to the 'check password script' without escaping shell meta-characters"
    publisher: Samba Project
  - quote: Unauthenticated Remote Code Execution in Samba printing subsystem
    publisher: oss-security / Samba team
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-05-29.md
---

The Samba Project shipped [coordinated releases 4.22.10 / 4.23.8 / 4.24.3 on 2026-05-27](https://www.samba.org/samba/security/CVE-2026-4408.html) covering six CVEs; two reach CVSS 10.0. `CVE-2026-4408` is a shell-metacharacter injection in `SamValidatePasswordChange` and `SamValidatePasswordReset` RPC handlers in the Samba DCE/RPC SAMR server — the client-controlled username is substituted into the `check password script` smb.conf option via `%u` without escaping. Prerequisites are non-default but real: a `check password script` containing `%u` must be configured, and `samba-dcerpcd` must be running as a system service (which requires the non-default `rpc start on demand helpers = no`). AD DCs are unaffected. [`CVE-2026-4480`](https://www.samba.org/samba/security/CVE-2026-4480.html) is a parallel injection in the print-command path: the `%J` substitution in the `print command` smb.conf option is fed the client-controlled job description without sanitisation; guest printing is on by default and the prerequisites are *raw / classic* printing backend (not CUPS / iprint). [ANSSI / CERT-FR advisory CERTFR-2026-AVI-0651](https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0651/) and the [Samba-team announcement on oss-security](https://www.openwall.com/lists/oss-security/2026/05/27/6) corroborate the disclosure. No public exploit observed. Patch immediately; if a same-day patch is impossible, remove `%u` from `check password script` and wrap `%J` in single quotes in `print command`.
