Improper Command Neutralization in YaST2 Samba Client by SUSE
CVE-2026-25706

7.5HIGH

Key Information:

Vendor

Suse

Vendor
CVE Published:
1 September 2026

What is CVE-2026-25706?

The YaST2 Samba Client in SUSE contains a vulnerability that arises from improper handling of special elements in operating system commands. This security issue can be exploited by an attacker who has access to an Active Directory environment, such as a rogue domain controller or a directory user with permissions to create objects. The flaw allows these attackers to execute arbitrary commands with root privileges on systems that are being integrated into the compromised Active Directory domain. This poses serious security risks, as it could lead to unauthorized access and potential system compromise.

Affected Version(s)

yast2-samba-client 0 <= 5.0.4

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alperen Keskin
.