Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Samba

13 known vulnerabilities

2
CRITICAL
5
HIGH
5
MEDIUM
1
LOW

Top Products

rsync 7 samba 6
13 CVEs
6.5
CVE-2026-58224

A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of rec

9.0
CVE-2026-4408

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain con

6.5
CVE-2026-2340

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections

7.1
CVE-2026-1933

A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to miss

8.0
CVE-2026-3012

A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabl

9.0
CVE-2026-4480

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the comma

7.0
CVE-2026-29518

Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that

3.1
CVE-2026-45232

Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connect

6.5
CVE-2026-43620

Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver

6.3
CVE-2026-43619

Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod,

8.1
CVE-2026-43618

Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit s

4.8
CVE-2026-43617

Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access

7.4
CVE-2026-41035

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiv

Frequently Asked Questions

How many CVEs affect Samba?

Samba has 13 CVE records in our database, including 2 critical and 5 high severity vulnerabilities.

What are the most severe Samba vulnerabilities?

Samba has 2 critical severity (CVSS 9.0+) and 5 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Samba vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Samba products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Samba Vulnerabilities

CyberStrike scans your infrastructure for Samba vulnerabilities and provides real-time remediation guidance.

Get Started