Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2026-1933— Samba: missing access check on reparse point operations

CVSS 7.1 · High
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-1933

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Samba: missing access check on reparse point operations
Source: NVD (National Vulnerability Database)
Vulnerability Description
A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations even on read-only exports. This could allow modification of SMB-visible file behavior, including converting files into symbolic links or other reparse point types.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
访问控制不恰当
Source: NVD (National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Red HatRed Hat Enterprise Linux 10-cpe:/o:redhat:enterprise_linux:10
Red HatRed Hat Enterprise Linux 6-cpe:/o:redhat:enterprise_linux:6
Red HatRed Hat Enterprise Linux 6-cpe:/o:redhat:enterprise_linux:6
Red HatRed Hat Enterprise Linux 7-cpe:/o:redhat:enterprise_linux:7
Red HatRed Hat Enterprise Linux 8-cpe:/o:redhat:enterprise_linux:8
Red HatRed Hat Enterprise Linux 9-cpe:/o:redhat:enterprise_linux:9
Red HatRed Hat OpenShift Container Platform 4-cpe:/a:redhat:openshift:4

II. Public POCs for CVE-2026-1933

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-1933

登录查看更多情报信息。

Patches & Fixes for CVE-2026-1933 (1)

Vendor Advisories for CVE-2026-1933 (1)

Other References for CVE-2026-1933 (1)

Same Patch Batch · Red Hat · 2026-05-27 · 5 CVEs total

CVE-2026-30128.0 HIGHSamba: group policy certificate enrollment uses http:// without validation
CVE-2026-97046.8 MEDIUMKeycloak: keycloak: privilege escalation due to oversized subject_token jwt
CVE-2026-23406.5 MEDIUMSamba: vfs_worm does not block directory modification
CVE-2026-96894.2 MEDIUMKeycloak: org.keycloak.protocol.oidc: http parameter pollution in oidc redirect uri allows

IV. Related Vulnerabilities

V. Comments for CVE-2026-1933

No comments yet


Leave a comment