Improper Command Neutralization in YaST2 Samba Client by SUSE
CVE-2026-25706
7.5HIGH
What is CVE-2026-25706?
The YaST2 Samba Client in SUSE contains a vulnerability that arises from improper handling of special elements in operating system commands. This security issue can be exploited by an attacker who has access to an Active Directory environment, such as a rogue domain controller or a directory user with permissions to create objects. The flaw allows these attackers to execute arbitrary commands with root privileges on systems that are being integrated into the compromised Active Directory domain. This poses serious security risks, as it could lead to unauthorized access and potential system compromise.
Affected Version(s)
yast2-samba-client 0 <= 5.0.4