openSUSE yast2-samba-client Command Injection Vulnerabilities Disclosed

openSUSE yast2-samba-client Command Injection Vulnerabilities Disclosed

First seen 1 Sep 2026, 02:01 UTC Linuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

Multiple command injection vulnerabilities affecting the yast2-samba-client have been disclosed, with CVE-2026-25706 identified as a significant risk. This vulnerability allows OS command injection via attacker-controlled OrganizationalUnit during an interactive domain join. The affected versions include yast2-samba-client 4.4.5, 4.5.4, and 4.6.2, which impact various SUSE Linux Enterprise and openSUSE systems. Patches have been released for these vulnerabilities, and users are advised to update their systems promptly. The vulnerabilities could potentially allow attackers to execute arbitrary commands on affected systems, posing a serious risk to system integrity and confidentiality. Current status indicates that the vulnerabilities are patched, but the potential for exploitation remains a concern.

Key Points: • CVE-2026-25706 allows OS command injection via Active Directory-supplied OrganizationalUnit. • Affected versions include yast2-samba-client 4.4.5, 4.5.4, and 4.6.2. • Patches are available, and users are urged to update their systems immediately.

Timeline

2026-09-01
Patches released for yast2-samba-client vulnerabilities
Updates for yast2-samba-client versions 4.4.5, 4.5.4, and 4.6.2 were released to address CVE-2026-25706.
Linuxsecurity
2026-09-01
CVE-2026-25706 disclosed
The vulnerability allows OS command injection during interactive domain joins, affecting multiple SUSE systems.
Linuxsecurity
2026-09-01
Multiple versions affected
Versions 4.4.5, 4.5.4, and 4.6.2 of yast2-samba-client are confirmed vulnerable to command injection.
Linuxsecurity