SQL injection in Samba - CVE-2026-58222
Published: July 28, 2026 / Updated: July 29, 2026
Samba
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to filter injection and trusted-request confusion in the LDAP Compare operation when handling LDAP Compare requests. A remote user can send crafted LDAP Compare requests to disclose sensitive information.
Confidential Active Directory attributes, including KDS root keys, can be queried by bypassing access checks.