{
  "threat_severity" : "Important",
  "public_date" : "2026-05-26T13:43:46Z",
  "bugzilla" : {
    "description" : "samba: Samba: Remote Code Execution in printing subsystem via unescaped job description",
    "id" : "2452232",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2452232"
  },
  "cvss3" : {
    "cvss3_base_score" : "9.0",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-78",
  "details" : [ "A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the \"print command\" setting via the \"%J\"\nsubstitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.", "A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the \"print command\" setting via the \"%J\"\nsubstitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system." ],
  "statement" : "The issue affects the Samba printing subsystem. Red Hat has classified this issue as Important severity rather than Critical.\nPrint servers configured with ```\"printing = cups\"``` or ```\"printing = iprint\"```, and print servers that do not have the ```\"%J\"``` substitution character in the \"print command\" setting are not affected.\nBy default, Red Hat Enterprise Linux ships with Samba configured to use CUPS-based printing ```printing = cups```. Hence, although the vulnerable code is present, it is not exploitable in default RHEL configurations. \nBecause exploitation depends on non-default Samba printing configurations and requires use of the %J substitution parameter within print command, the attack complexity is considered High (AC:H), reducing the likelihood of exploitation in standard deployments.",
  "acknowledgement" : "Red Hat would like to thank Arjun Basnet (Securin Labs), John Walker (ZeroPath), and Ron Ben Yizhak (SafeBreach) for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-06-03T00:00:00Z",
    "advisory" : "RHSA-2026:22963",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "samba-0:4.23.5-109.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10.0 Extended Update Support",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28055",
    "cpe" : "cpe:/o:redhat:enterprise_linux_eus:10.0",
    "package" : "samba-0:4.21.3-114.el10_0.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28132",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "samba-0:4.10.16-26.el7_9.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28132",
    "cpe" : "cpe:/o:redhat:rhel_els:7",
    "package" : "samba-0:4.10.16-26.el7_9.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-03T00:00:00Z",
    "advisory" : "RHSA-2026:22644",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "samba-0:4.19.4-16.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-03T00:00:00Z",
    "advisory" : "RHSA-2026:22644",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8",
    "package" : "samba-0:4.19.4-16.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28058",
    "cpe" : "cpe:/o:redhat:rhel_aus:8.4",
    "package" : "samba-0:4.13.3-12.el8_4.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28058",
    "cpe" : "cpe:/o:redhat:rhel_eus_long_life:8.4",
    "package" : "samba-0:4.13.3-12.el8_4.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28057",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.6",
    "package" : "samba-0:4.15.5-16.el8_6.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28057",
    "cpe" : "cpe:/a:redhat:rhel_eus_long_life:8.6",
    "package" : "samba-0:4.15.5-16.el8_6.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28056",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.8",
    "package" : "samba-0:4.17.5-7.el8_8.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28056",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.8",
    "package" : "samba-0:4.17.5-7.el8_8.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-06-10T00:00:00Z",
    "advisory" : "RHSA-2026:25049",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "samba-0:4.23.5-10.el9_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-06-10T00:00:00Z",
    "advisory" : "RHSA-2026:25049",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9",
    "package" : "samba-0:4.23.5-10.el9_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28054",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.2",
    "package" : "samba-0:4.17.5-105.el9_2.5"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28053",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.4",
    "package" : "samba-0:4.19.4-105.el9_4.4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-06-15T00:00:00Z",
    "advisory" : "RHSA-2026:25979",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "samba-0:4.21.3-14.el9_6.1"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Out of support scope",
    "package_name" : "samba",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Out of support scope",
    "package_name" : "samba4",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Not affected",
    "package_name" : "rhcos",
    "cpe" : "cpe:/a:redhat:openshift:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-4480\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-4480\nhttps://bugzilla.samba.org/show_bug.cgi?id=16033" ],
  "name" : "CVE-2026-4480",
  "mitigation" : {
    "value" : "Remove ```\"%J\"``` from the \"print command\" in ```smb.conf``` entry.",
    "lang" : "en:us"
  },
  "csaw" : false
}