Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who controls the content of an Active Directory directory tree - a rogue domain controller, or a directory user delegated the right to create objects - to execute arbitrary commands as root on a machine being joined to that domain.
This issue affects yast2-samba-client through 5.0.4.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=1272776 |
|
History
Tue, 01 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Suse
Suse yast2-samba-client |
|
| Vendors & Products |
Suse
Suse yast2-samba-client |
Tue, 01 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 01 Sep 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who controls the content of an Active Directory directory tree - a rogue domain controller, or a directory user delegated the right to create objects - to execute arbitrary commands as root on a machine being joined to that domain. This issue affects yast2-samba-client through 5.0.4. | |
| Title | yast2-samba-client: OS command injection via attacker-controlled Organizational Unit (Active Directory-supplied) | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: suse
Published: 2026-09-01T09:51:22.208Z
Updated: 2026-09-02T03:55:30.645Z
Reserved: 2026-02-05T15:37:24.184Z
Link: CVE-2026-25706
Updated: 2026-09-01T12:20:29.623Z
Status : Awaiting Analysis
Published: 2026-09-01T10:17:12.993
Modified: 2026-09-02T04:17:52.697
Link: CVE-2026-25706
No data.