Command injection in Samba - CVE-2026-4480
Published: May 27, 2026
Samba
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to command injection in the Samba printing subsystem when invoking a print command that uses the %J substitution character. A remote attacker can submit crafted print job data that reaches the print command to execute arbitrary code.
Exploitation requires a Samba print server with a configured "print command" that uses the %J substitution character.