CVE-2026-4480

Published May 26, 2026

Last updated 6 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-4480 describes a vulnerability found within the Samba printing subsystem. This flaw arises because Samba transmits the client-controlled job description string to the command configured by the "print command" setting, utilizing the "%J" substitution character, without adequately escaping shell meta characters. Consequently, a remote attacker can exploit this vulnerability by submitting a specially crafted print job description that incorporates unescaped shell characters. This action could lead to remote code execution on the affected system.

Description
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.
Source
secalert@redhat.com
NVD status
Modified
Products
openshift_container_platform, samba, enterprise_linux

Risk scores

CVSS 3.1

Type
Secondary
Base score
9
Impact score
6
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

secalert@redhat.com
CWE-78
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
CWE-78

Social media

Hype score
Not currently trending
  1. Top 5 Trending CVEs: 1 - CVE-2025-8088 2 - CVE-2026-4480 3 - CVE-2026-42271 4 - CVE-2026-23111 5 - CVE-2026-3300 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    9 Jun 2026

    100 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. ⚠️ Vulnerabilidades en productos Samba ❗ CVE-2026-4480 ❗ CVE-2026-4408 ❗ CVE-2026-3012 ➡️ Más info: https://t.co/B1yfTtTuWW https://t.co/tDy1a4OFXL

    @CERTpy

    3 Jun 2026

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Sambaに2件の致命的な脆弱性-CVE-2026-4408とCVE-2026-4480|セキュリティ対策Lab https://t.co/xX9BTAA1fc "CVSS 10.0と評価された2件の認証不要リモートコード実行な脆弱性です。CVE-2026-4480はSambaの印刷サブシステム、CVE-2026-4408

    @catnap707

    2 Jun 2026

    168 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Sambaに2件の致命的な脆弱性-CVE-2026-4408とCVE-2026-4480 https://t.co/MChVczM4fZ #セキュリティ対策Lab #security #securitynews

    @securityLab_jp

    2 Jun 2026

    110 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. SambaがCVSSスコア10の脆弱性2件を修正。印刷サブシステムのCVE-2026-4480とパスワード検証のCVE-2026-4408。その他、高深刻度のもの2件を含む複数の脆弱性も修正されている。 https://t.co/Zf5ERcKYKr

    @__kokumoto

    29 May 2026

    809 Impressions

    0 Retweets

    7 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  6. Warning: #Samba has released a security bulletin covering six #CVEs including #CVE-2026-4480 (CVSS:10.0) and #CVE-2026-4408 (CVSS:10.0). Both lead to Remote Code Execution #RCE. Find out more at https://t.co/8k3sdo9b6e #Patch #Patch #Patch

    @CCBalert

    27 May 2026

    220 Impressions

    2 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.