Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Poison Claude Sells AI Tokens From Fake Accounts and Free Credits
August 5, 2026
Greatness PhaaS Bypasses Email Security, MFA to Hijack Microsoft 365 Accounts
August 5, 2026
Microsoft Awards Record $20M to 562 Researchers in Biggest Bug Bounty Year
August 5, 2026
Home/CyberSecurity News/Critical Samba CVE-2022-26925 Lets Attackers Run Remote Code
CyberSecurity News

Critical Samba CVE-2022-26925 Lets Attackers Run Remote Code

Key Takeaways A critical remote code execution (RCE) vulnerability, CVE-2026-4480, has been discovered in Samba’s printing subsystem. The flaw allows unauthenticated attackers to execute...

David kimber
David kimber
May 29, 2026 4 Min Read
63 0

Key Takeaways

  • A critical remote code execution (RCE) vulnerability, CVE-2026-4480, has been discovered in Samba’s printing subsystem.
  • The flaw allows unauthenticated attackers to execute arbitrary commands on vulnerable Samba servers.
  • It affects Samba installations configured with a specific “print command” parameter that includes the %J substitution.
  • The vulnerability carries a maximum CVSS v3.1 score of 10.0, indicating extreme severity and ease of exploitation.
  • Patches are available in Samba versions 4.22.10, 4.23.8, and 4.24.3, and immediate upgrade is strongly recommended.

A severe flaw in the Samba printing subsystem could allow remote code execution (RCE) on susceptible systems, posing a significant risk to organizations utilizing the popular file and print service. Identified as CVE-2026-4480, this critical vulnerability enables unauthenticated attackers to compromise affected machines by injecting malicious commands.

Table Of Content

  • Key Takeaways
  • Samba Vulnerability Details
  • What You Should Do

The severity of this vulnerability is underscored by its CVSS v3.1 score of 10.0, the highest possible rating, indicating both its profound impact and the straightforward nature of its exploitation.

Samba, a cornerstone for file and print sharing across Linux and Unix environments, becomes vulnerable when its “print command” configuration incorporates the %J substitution parameter. This parameter is designed to embed a client-provided print job description string directly into a shell command.

The core issue lies in the lack of proper sanitization; special characters within the %J parameter are not escaped, allowing attackers to inject arbitrary shell commands that the server then executes.

Samba Vulnerability Details

As detailed in the official advisory, the vulnerability stems from Samba’s failure to cleanse shell meta-characters embedded within the %J variable. This oversight permits an attacker to craft a specially designed print job that contains malicious shell instructions, which are subsequently executed by the server.

A critical aspect of this vulnerability is that many Samba deployments allow guest users to submit print jobs by default. This common configuration means that exploiting CVE-2026-4480 often requires no prior authentication, significantly broadening the potential attack surface for threat actors.

However, not all Samba configurations are at risk. Systems configured with “printing = cups” or “printing = iprint” are immune to this specific flaw. Additionally, servers whose print command configuration does not include the %J substitution parameter remain secure.

The vulnerability was independently reported by security researchers from SafeBreach, ZeroPath, and Securin Labs. The Samba Team has acknowledged the flaw and promptly released patches to mitigate the risk. These fixes are integrated into Samba versions 4.22.10, 4.23.8, and 4.24.3.

Administrators are strongly urged to upgrade their Samba installations to one of the patched versions without delay. The official patches are readily available on the Samba security page.

For situations where immediate patching is not feasible, temporary mitigations can be applied. One approach involves enclosing the %J parameter in single quotes (‘%J’), which can limit, but not entirely eliminate, the potential for command injection. The most effective workaround, if an immediate upgrade is impossible, is to completely remove the %J parameter from the smb.conf “print command” configuration.

This vulnerability carries substantial implications for enterprise environments, particularly those relying on legacy Samba configurations or exposing print services to their networks. Successful exploitation of this flaw could grant attackers full control over compromised systems, potentially leading to severe consequences such such as data breaches, lateral movement within the network, or the deployment of ransomware.

Organizations are advised to conduct thorough audits of their Samba configurations, restrict guest access to print services where feasible, and actively monitor for any unusual print job activity, which could serve as an indicator of compromise. Given the simplicity of its exploitation and its critical severity, CVE-2026-4480 demands immediate attention and should be prioritized as a top patching requirement.

This incident serves as a stark reminder of the persistent risks associated with command injection vulnerabilities, especially in network-exposed legacy service configurations, emphasizing the paramount importance of robust input handling practices.

What You Should Do

  • Upgrade Immediately: Apply the official patches by upgrading Samba to versions 4.22.10, 4.23.8, 4.24.3, or later.
  • Review Configurations: Audit your smb.conf file to check if the “print command” includes the %J substitution parameter.
  • Remove %J Parameter: If immediate patching is not possible, remove the %J parameter entirely from the “print command” in your smb.conf.
  • Enclose %J in Quotes: As a less ideal temporary measure, if %J cannot be removed, enclose it in single quotes (e.g., ' %J ') to limit injection potential.
  • Restrict Guest Access: Limit or disable guest user access to print services if not strictly necessary for business operations.
  • Monitor for Anomalies: Implement monitoring for unusual print job activity or suspicious shell command executions on Samba servers.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCVEExploitPatchransomwareSecurityVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Malicious RVTools Installer Abuses Sectigo Certificate to Bypass SmartScreen Warnings

Next Post

Microsoft System64 Malware Exfiltrates Data via HuggingFace Datasets

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical TP-Link Omada ZTP Flaws Let Attackers Hijack Routers, Execute Root Code
August 5, 2026
Critical OVSwrap Linux Vulnerability (CVE-2024-3094) Lets Attackers Gain Root
August 5, 2026
Django Patches Four High-Severity Vulnerabilities in Versions 6.0.8 and 5.2.17
August 5, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us