Command Injection Affecting samba package, versions [,4.24.3)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
13.93% (97th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-SAMBA-16964914
  • published28 May 2026
  • disclosed26 May 2026
  • creditArjun Basnet, John Walker, Ron Ben Yizhak

Introduced: 26 May 2026

CVE-2026-4480  (opens in a new tab)
CWE-78  (opens in a new tab)

How to fix?

Upgrade samba to version 4.24.3 or higher.

Overview

Affected versions of this package are vulnerable to Command Injection via the print command process. An attacker can execute arbitrary commands on the system by submitting a crafted print job description containing unescaped shell characters.

Workaround

This vulnerability can be mitigated by removing %J from the print command entry in smb.conf.

CVSS Base Scores

version 4.0
version 3.1