CVE-2026-3012: Samba: group policy certificate enrollment uses http:// without validation

Published Mar 13, 2026
·
Updated

A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.

Other sources

group policy certificate enrollment uses http:// without validation

Debian

Affected Software

5 affected componentsFixes available
debian/samba<=2:4.13.13+dfsg-1~deb11u6, <=2:4.13.13+dfsg-1~deb11u7, <=2:4.17.12+dfsg-0+deb12u3, <=2:4.22.8+dfsg-0+deb13u1, <=2:4.24.2+dfsg-1
2:4.17.12+dfsg-0+deb12u42:4.22.8+dfsg-0+deb13u22:4.24.3+dfsg-1
redhat OpenShift Container Platform=4.0
Samba Samba>=4.16.0<4.21.0
redhat Enterprise Linux=7.0
redhat Enterprise Linux=9.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/samba to a version that resolves this vulnerability.

    Fixed in 2:4.17.12+dfsg-0+deb12u4Fixed in 2:4.22.8+dfsg-0+deb13u2Fixed in 2:4.24.3+dfsg-1
  2. Configuration

    When Samba group policy certificate enrollment is enabled, prevent retrieval of CA certificates over an unencrypted HTTP connection (http:// without validation) so CA certificates are not installed into the local trust store without proper verification.

    Samba (Group Policy certificate auto-enrollment) certificate auto-enrollment retrieval protocol/validation = Disable HTTP/unvalidated CA certificate retrieval; require validation (no insecure http:// retrieval)

Event History

Mar 13, 2026
Data Sourced
via Red Hat·01:05 PM
DescriptionSeverityAffected Software
May 26, 2026
Data Sourced
via Ubuntu·04:09 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·04:10 PM
DescriptionAffected Software
May 27, 2026
CVE Published
via MITRE·10:02 AM
Data Sourced
via MITRE·10:02 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via Launchpad·04:11 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-3012?

The severity of CVE-2026-3012 is rated as high with a score of 8.

2

How does CVE-2026-3012 affect Samba?

CVE-2026-3012 affects Samba by allowing it to retrieve CA certificates over unencrypted HTTP without proper validation during certificate auto-enrollment.

3

What are the potential risks associated with CVE-2026-3012?

The potential risks of CVE-2026-3012 include the possibility of installing a malicious CA certificate, leading to compromised trust within the network.

4

How can I fix CVE-2026-3012?

To fix CVE-2026-3012, ensure that certificate auto-enrollment is configured to use secure connections and implement proper validation checks.

5

Which software versions are impacted by CVE-2026-3012?

CVE-2026-3012 impacts Red Hat Enterprise Linux, Debian/Samba, Red Hat OpenShift Container Platform, and Samba.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203