CVE-2026-58222

EUVD-2026-51158
A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to properly validate user-supplied attribute names and executes the resulting internal database search in a trusted context, bypassing normal Access Control List (ACL) enforcement. An authenticated low-privilege domain user can exploit these flaws to disclose confidential Active Directory attributes that would normally be inaccessible. The disclosed information may be leveraged to derive sensitive authentication material, potentially leading to privilege escalation and complete domain compromise. For example: In deployments configured with Group Managed Service Accounts (gMSAs), an attacker can extract the "msKds-RootKeyData" attribute and derive gMSA passwords offline, potentially leading to complete domain compromise if privileged gMSAs are present.
LDAP Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 38.73%
Debian logo
Debian Releases
Debian Product
Codename
samba
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
ignored
forky
2:4.24.6+dfsg-1
fixed
sid
2:4.24.7+dfsg-1
fixed
trixie
vulnerable
trixie (security)
2:4.22.10+dfsg-0+deb13u2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
samba
bionic
needs-triage
focal
needs-triage
jammy
Fixed 2:4.15.13+dfsg-0ubuntu1.13
released
noble
Fixed 2:4.19.5+dfsg-4ubuntu9.7
released
resolute
Fixed 2:4.23.6+dfsg-1ubuntu2.2
released
trusty
needs-triage
xenial
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
ctdb
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
ctdb-tests
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
libsmbclient
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
libsmbclient-devel
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
libwbclient
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
libwbclient-devel
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
samba
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
samba-client
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
samba-client-libs
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
samba-common
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
samba-common-libs
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
samba-common-tools
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
samba-dc
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
samba-dc-libs
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
samba-debuginfo
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
samba-devel
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
samba-krb5-printing
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
samba-libs
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
samba-pidl
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
samba-python
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
samba-python-test
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
samba-test
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
samba-test-libs
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
samba-vfs-glusterfs
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
samba-winbind
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
samba-winbind-clients
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
samba-winbind-krb5-locator
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed
samba-winbind-modules
Amazon Linux 2
0:4.10.16-24.amzn2.0.9
fixed