Improper Certificate Validation in Samba - CVE-2026-3012
Published: May 27, 2026
Samba
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise certificate trust during auto-enrolment.
The vulnerability exists due to improper certificate validation in auto-enrolment GPO certificate installation when fetching a CA certificate over HTTP without verification. A remote attacker can tamper with the certificate retrieval process to compromise certificate trust during auto-enrolment.
The issue arises because HTTP was trusted for bootstrapping a certificate chain even when a more secure encrypted LDAP channel was available.