CVE-2026-44076: Shell injection via volume path
Published May 21, 2026
·Updated
Insufficient sanitization of volume paths in Netatalk 3.1.0 through 4.4.2 allows a local privileged user to inject OS commands and execute arbitrary code via a crafted volume path.
Affected Software
1 affected component
Netatalk Netatalk>=3.1.0<=4.4.2
Event History
May 21, 2026
CVE Published
via MITRE·07:35 AM
Data Sourced
via MITRE·07:35 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-44076?
The severity of CVE-2026-44076 is medium, rated at 6.7.
2
What vulnerabilities are associated with CVE-2026-44076?
CVE-2026-44076 is associated with shell injection vulnerabilities via the volume path in Netatalk.
3
How do I fix CVE-2026-44076?
To fix CVE-2026-44076, update Netatalk to version 4.4.3 or later.
4
What versions of Netatalk are affected by CVE-2026-44076?
Netatalk versions 3.1.0 through 4.4.2 are affected by CVE-2026-44076.
5
What type of vulnerability is CVE-2026-44076 classified as?
CVE-2026-44076 is classified as an OS command injection vulnerability.