VDB

CVE-2026-58222

CVE-2026-58222 PUBLISHED CVSS 8.8 HIGH

Reported by redhat · Published July 30, 2026

A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to properly validate user-supplied attribute names and executes the resulting internal database search in a trusted context, bypassing normal Access Control List (ACL) enforcement. An authenticated low-privilege domain user can exploit these flaws to disclose confidential Active Directory attributes that would normally be inaccessible. The disclosed information may be leveraged to derive sensitive authentication material, potentially leading to privilege escalation and complete domain compromise. For example: In deployments configured with Group Managed Service Accounts (gMSAs), an attacker can extract the "msKds-RootKeyData" attribute and derive gMSA passwords offline, potentially leading to complete domain compromise if privileged gMSAs are present.

Risk Scores

CVSS 3.1
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 6
Red HatRed Hat Enterprise Linux 6
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat Enterprise Linux 6
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 6
alpinesamba0, 0, 0
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat Enterprise Linux 9

Timeline

  • Jul 28, 2026 CVE Published
  • Jul 30, 2026 Coalition ESS Score
  • Jul 30, 2026 CVE Updated
  • Aug 7, 2026 EPSS Score

References

  • vdb-entryx_refsource_REDHAT
  • RHBZ#2502722 issue-trackingx_refsource_REDHAT
Open in Interactive Console →
$ Console Community · 100/wk Open console ›