CVE-2026-1933: Samba: missing access check on reparse point operations
A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations even on read-only exports. This could allow modification of SMB-visible file behavior, including converting files into symbolic links or other reparse point types.
Other sources
Missing access check on reparse point operations
— Debian
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/sambato a version that resolves this vulnerability.Fixed in 2:4.13.13+dfsg-1~deb11u6Fixed in 2:4.13.13+dfsg-1~deb11u7Fixed in 2:4.17.12+dfsg-0+deb12u3Fixed in 2:4.17.12+dfsg-0+deb12u4Fixed in 2:4.22.8+dfsg-0+deb13u2Fixed in 2:4.24.3+dfsg-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1933?
The severity of CVE-2026-1933 is high with a CVSS score of 7.1.
How do I fix CVE-2026-1933?
To fix CVE-2026-1933, ensure that access controls are properly configured on Samba shares to prevent unauthorized reparse point actions.
What does CVE-2026-1933 affect?
CVE-2026-1933 affects Samba on platforms such as Red Hat Enterprise Linux, Debian/Samba, and Red Hat OpenShift Container Platform.
What type of vulnerability is CVE-2026-1933?
CVE-2026-1933 is a flaw related to missing access checks on reparse point operations in Samba.
Who can exploit CVE-2026-1933?
Authenticated users with underlying filesystem write permissions can exploit CVE-2026-1933 to manipulate reparse points.