FAIL › dossier
samba
VENDOR· dossier confidence 20%
Samba, an open-source file and print services suite, has experienced critical vulnerabilities that allowed for remote code execution. The vendor has struggled with repeated unpatched vulnerabilities, indicating potential security lapses in their product and processes.
PROFILE
CategoryvendorWhat they doSamba is an open-source software suite that provides file and print services for all kinds of SMB/CIFS protocol clients, as well as a standalone file server.
Websitehttps://www.samba.org/ ↗
SECURITY POSTURE
The vendor has faced multiple security vulnerabilities, indicating a potential lack of robust security posture.
Notable failures
- CVE-2017-7494: Allowed attackers to upload and execute arbitrary code on vulnerable servers via writable shares.
- CVE-2026-4408: A flaw was found in Samba that could be exploited by a remote attacker with a misconfiguration in file servers and classic domain controllers.
Patterns: Repeated unpatched vulnerabilities; Misconfiguration leading to remote code execution
FAILURE HISTORY · 4
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2023-03-30 | CVE-2017-7494 | critical | Samba's CVE-2017-7494 allowed attackers to upload and execute arbitrary code on vulnerable servers via writable shares. |
| 2023-03-30 | CVE-2017-7494 | critical | Samba's CVE-2017-7494 allowed attackers to upload and execute arbitrary code on vulnerable servers via writable shares. |
| 2026-05-28 | CVE-2026-4408 | critical | A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed |
| 2026-05-28 | CVE-2026-4408 | critical | A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed |
DOSSIER SOURCES
- Samba: Releases, patches & end-of-life - versio.io · www.versio.io
- Samba: Releases, patches & end-of-life - Versio.io · www.versio.io
- oss-security - Fwd: Heads-up: Upcoming important Samba security ... · www.openwall.com
Open questions: How has Samba addressed the recurring security issues? · What measures has the vendor taken to improve its security posture?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-27 03:43:12.203898+00:00