CVE-2026-3012: Samba: group policy certificate enrollment uses http:// without validation
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.
Other sources
group policy certificate enrollment uses http:// without validation
— Debian
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/sambato a version that resolves this vulnerability.Fixed in 2:4.17.12+dfsg-0+deb12u4Fixed in 2:4.22.8+dfsg-0+deb13u2Fixed in 2:4.24.3+dfsg-1 - Configuration
When Samba group policy certificate enrollment is enabled, prevent retrieval of CA certificates over an unencrypted HTTP connection (http:// without validation) so CA certificates are not installed into the local trust store without proper verification.
Samba (Group Policy certificate auto-enrollment) certificate auto-enrollment retrieval protocol/validation = Disable HTTP/unvalidated CA certificate retrieval; require validation (no insecure http:// retrieval)
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3012?
The severity of CVE-2026-3012 is rated as high with a score of 8.
How does CVE-2026-3012 affect Samba?
CVE-2026-3012 affects Samba by allowing it to retrieve CA certificates over unencrypted HTTP without proper validation during certificate auto-enrollment.
What are the potential risks associated with CVE-2026-3012?
The potential risks of CVE-2026-3012 include the possibility of installing a malicious CA certificate, leading to compromised trust within the network.
How can I fix CVE-2026-3012?
To fix CVE-2026-3012, ensure that certificate auto-enrollment is configured to use secure connections and implement proper validation checks.
Which software versions are impacted by CVE-2026-3012?
CVE-2026-3012 impacts Red Hat Enterprise Linux, Debian/Samba, Red Hat OpenShift Container Platform, and Samba.