This issue affects yast2-samba-client through 5.0.4.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=1272776 |
|
Tue, 01 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Suse
Suse yast2-samba-client |
|
| Vendors & Products |
Suse
Suse yast2-samba-client |
Tue, 01 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 01 Sep 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who controls the content of an Active Directory directory tree - a rogue domain controller, or a directory user delegated the right to create objects - to execute arbitrary commands as root on a machine being joined to that domain. This issue affects yast2-samba-client through 5.0.4. | |
| Title | yast2-samba-client: OS command injection via attacker-controlled Organizational Unit (Active Directory-supplied) | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2026-09-01T12:20:37.381Z
Reserved: 2026-02-05T15:37:24.184Z
Link: CVE-2026-25706
Updated: 2026-09-01T12:20:29.623Z
Status : Awaiting Analysis
Published: 2026-09-01T10:17:12.993
Modified: 2026-09-01T20:54:51.287
Link: CVE-2026-25706
No data.
OpenCVE Enrichment
Updated: 2026-09-01T14:15:08Z