CVE-2026-59260
EUVD-2026-4323312.07.2026, 12:16
OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-line arguments. Attackers can pass arbitrary Samba global options such as message command to a root smbd process, triggering command execution when SMB protocol messages are processed.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| openwrt | luci | 𝑥 < 24.10.8 | CNA |
| openwrt | luci | 25.12.0 ≤ 𝑥 < 25.12.5 | CNA |
Common Weakness Enumeration