CVE-2026-4480: Samba: samba: remote code execution in printing subsystem via unescaped job description
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.
Other sources
Samba: Unauthenticated Remote Code Execution in Samba printing subsystem
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/sambato a version that resolves this vulnerability.Fixed in 2:4.17.12+dfsg-0+deb12u4Fixed in 2:4.22.8+dfsg-0+deb13u2Fixed in 2:4.24.3+dfsg-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4480?
The severity of CVE-2026-4480 is rated as high with a score of 8.5.
How do I fix CVE-2026-4480?
To fix CVE-2026-4480, upgrade Samba to the latest version that includes the patch for this vulnerability.
What kind of vulnerability is CVE-2026-4480?
CVE-2026-4480 is an OS Command Injection vulnerability in the Samba printing subsystem.
Who is affected by CVE-2026-4480?
Users of Samba who have configured the 'print command' setting are affected by CVE-2026-4480.
Can CVE-2026-4480 lead to remote code execution?
Yes, CVE-2026-4480 can allow a remote attacker to execute arbitrary code due to unescaped shell meta characters in the job description.