Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who controls the content of an Active Directory directory tree - a rogue domain controller, or a directory user delegated the right to create objects - to execute arbitrary commands as root on a machine being joined to that domain.
This issue affects yast2-samba-client through 5.0.4.
This issue affects yast2-samba-client through 5.0.4.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=1272776 |
|
History
Tue, 01 Sep 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who controls the content of an Active Directory directory tree - a rogue domain controller, or a directory user delegated the right to create objects - to execute arbitrary commands as root on a machine being joined to that domain. This issue affects yast2-samba-client through 5.0.4. | |
| Title | yast2-samba-client: OS command injection via attacker-controlled Organizational Unit (Active Directory-supplied) | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2026-09-01T09:51:22.208Z
Reserved: 2026-02-05T15:37:24.184Z
Link: CVE-2026-25706
No data.
Status : Received
Published: 2026-09-01T10:17:12.993
Modified: 2026-09-01T10:17:12.993
Link: CVE-2026-25706
No data.
OpenCVE Enrichment
Updated: 2026-09-01T11:30:03Z
Weaknesses