CVE-2026-3012

Published May 27, 2026

Last updated 2 days ago

Overview

Description
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.
Source
secalert@redhat.com
NVD status
Modified
Products
openshift_container_platform, samba, enterprise_linux

Risk scores

CVSS 3.1

Type
Primary
Base score
6.8
Impact score
5.2
Exploitability score
1.6
Vector string
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity
MEDIUM

Weaknesses

secalert@redhat.com
CWE-345
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
CWE-345

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.