SQL injection in Samba - CVE-2026-58222

 

SQL injection in Samba - CVE-2026-58222

Published: July 28, 2026 / Updated: July 29, 2026


Vulnerability identifier: #VU139945
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-58222
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
Samba

Detailed vulnerability description

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to filter injection and trusted-request confusion in the LDAP Compare operation when handling LDAP Compare requests. A remote user can send crafted LDAP Compare requests to disclose sensitive information.

Confidential Active Directory attributes, including KDS root keys, can be queried by bypassing access checks.


How to mitigate CVE-2026-58222

Install security update from vendor's website.

Sources