CVE-2026-44051: Arbitrary file read via attacker-controlled symlink creation
Published May 21, 2026
·Updated
An improper link resolution vulnerability in Netatalk 3.0.2 through 4.4.2 allows a remote authenticated attacker to read arbitrary files or overwrite arbitrary files via attacker-controlled symlink creation.
Affected Software
1 affected component
Netatalk Netatalk>=3.0.2<=4.4.2
Event History
May 21, 2026
CVE Published
via MITRE·07:34 AM
Data Sourced
via MITRE·07:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-44051?
CVE-2026-44051 has a severity rating of 8.1, classified as high.
2
How do I fix CVE-2026-44051?
To fix CVE-2026-44051, update Netatalk to a version later than 4.4.2.
3
What is the impact of CVE-2026-44051?
The impact of CVE-2026-44051 allows remote authenticated attackers to read or overwrite arbitrary files via symlink creation.
4
Which versions of Netatalk are affected by CVE-2026-44051?
Netatalk versions 3.0.2 through 4.4.2 are affected by CVE-2026-44051.
5
Is user intervention required to exploit CVE-2026-44051?
Yes, a remote authenticated attacker requires user-level access to exploit CVE-2026-44051.