Multiple Samba Remote Code Execution Vulnerabilities (CVE-2026-4480, CVE-2026-4408)
39095
02 October 2026
02 October 2026
CLOSED
LOW
CVE-2026-4480, CVE-2026-4408
|
Brocade Security Advisory ID |
BSA-2026-4107 |
|
Component |
Samba |
|
|
|
Brocade Security Advisory: Multiple Samba Remote Code Execution Vulnerabilities
Brocade Assessed Risk: Low
Affected CVE: CVE-2026-4480, CVE-2026-4408
Brocade Security Advisory ID: 2026-4107
Summary
Brocade has released a security advisory addressing two Remote Code Execution (RCE) vulnerabilities in upstream Samba software: CVE-2026-4480 and CVE-2026-4408. Both vulnerabilities result from improper input sanitization (CWE-78), which allows unescaped data to be passed into system commands or scripts.
Vulnerability Details
1. CVE-2026-4480: Samba Remote Code Execution in Printing Subsystem
Severity / CVSS v3 Base Score: Critical / 9.0
Common Weakness Enumeration: CWE-78 (Improper Neutralization of Special Elements used in an OS Command)
Description: An unescaped job description within Samba's printing subsystem allows remote attackers to inject arbitrary OS commands. Successful exploitation could lead to full remote code execution in the context of the running Samba service.
2. CVE-2026-4408: Samba RCE via Improper Character Escaping in Password Script
Severity / CVSS v3 Base Score: Medium / 5.9
Common Weakness Enumeration: CWE-78 (Improper Neutralization of Special Elements used in an OS Command
Description: Improper character escaping within the 'check password script' configuration parameter permits an attacker to execute arbitrary system commands under specific conditions when password checks are evaluated.
Products Confirmed Not Affected
Brocade ASCG - [VEX]:Vulnerable_code_not_in_execute_path
Brocade SANnav - [VEX]: Vulnerable_code_not_in_execute_path
Solution
A security update is provided in Brocade ASCG 3.5.0 OVA
Solution & Remediation
Brocade recommends that administrators upgrade affected installations to the patched release listed below as soon as possible.
Revision History
|
Version |
Change |
Date |
|
1.0 |
Initial Publication |
9/30/2026 |
Disclaimer
THIS DOCUMENT IS PROVIDED ON AN AS-IS BASIS SOLELY FOR INFORMATIONAL PURPOSES AND DOES NOT IMPLY ANY KIND OF GUARANTY OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. YOUR USE OF THE INFORMATION CONTAINED HEREIN IS AT YOUR OWN RISK. ALL INFORMATION PROVIDED HEREIN IS BASED ON BROCADE'S CURRENT KNOWLEDGE AND UNDERSTANDING OF THE VULNERABILITY AND IMPACT TO BROCADE HARDWARE AND SOFTWARE PRODUCTS. BROCADE RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.