This issue affects yast2-samba-client through 5.0.4.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=1272776 |
|
Tue, 01 Sep 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who controls the content of an Active Directory directory tree - a rogue domain controller, or a directory user delegated the right to create objects - to execute arbitrary commands as root on a machine being joined to that domain. This issue affects yast2-samba-client through 5.0.4. | |
| Title | yast2-samba-client: OS command injection via attacker-controlled Organizational Unit (Active Directory-supplied) | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2026-09-01T09:51:22.208Z
Reserved: 2026-02-05T15:37:24.184Z
Link: CVE-2026-25706
No data.
Status : Received
Published: 2026-09-01T10:17:12.993
Modified: 2026-09-01T10:17:12.993
Link: CVE-2026-25706
No data.
OpenCVE Enrichment
Updated: 2026-09-01T11:30:03Z
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')