Samba Vulnerability in NTFS-Style Reparse Points in Read-Only Shares
CVE-2026-1933
7.1HIGH
What is CVE-2026-1933?
A security issue exists in Samba related to its handling of NTFS-style reparse points on shares configured with read-only permissions. This flaw enables authenticated users with write access on the underlying filesystem to create or modify reparse point metadata via SMB operations, even when the shares are set to read-only. As a result, it may lead to unintended alterations in file behavior visible through SMB, potentially allowing files to be transformed into symbolic links or other types of reparse points, which can pose significant security risks.
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Asim Viladi Oglu Manizada for reporting this issue.