CVE-2026-44068: EA path traversal via incomplete sanitization
Published May 21, 2026
·Updated
Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write to files outside the intended metadata namespace via crafted EA names.
Affected Software
1 affected component
Netatalk Netatalk>=2.1.0<=4.4.2
Event History
May 21, 2026
CVE Published
via MITRE·07:34 AM
Data Sourced
via MITRE·07:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-44068?
The severity of CVE-2026-44068 is rated high with a score of 7.6.
2
How do I fix CVE-2026-44068?
To fix CVE-2026-44068, upgrade to Netatalk version 4.4.3 or later.
3
What vulnerability does CVE-2026-44068 exploit?
CVE-2026-44068 exploits a path traversal vulnerability due to incomplete sanitization in Netatalk.
4
Which versions of Netatalk are affected by CVE-2026-44068?
Netatalk versions 2.1.0 through 4.4.2 are affected by CVE-2026-44068.
5
What are the potential impacts of CVE-2026-44068?
CVE-2026-44068 can lead to information disclosure by allowing unauthorized access to files outside the intended directory.