Race Condition in Netatalk Affects Multiple Versions
CVE-2026-44059

3.9LOW

Key Information:

Vendor

Netatalk

Status
Vendor
CVE Published:
21 May 2026

What is CVE-2026-44059?

A race condition exists within the privilege toggle mechanism of Netatalk versions 2.2.5 through 4.4.2. This flaw can be exploited by a local attacker to gain unauthorized access to sensitive information, manipulate limited data, or lead to minor disruptions in service availability. This type of vulnerability potentially undermines the integrity and reliability of applications built on the affected Netatalk versions.

Affected Version(s)

Netatalk 2.2.5 <= 4.4.2

Netatalk 4.5.0

References

CVSS V3.1

Score:
3.9
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Basnet from Securin
.