Local Command Execution Vulnerability in Netatalk by Netatalk Foundation
CVE-2026-44072

2.5LOW

Key Information:

Vendor

Netatalk

Status
Vendor
CVE Published:
21 May 2026

What is CVE-2026-44072?

A vulnerability exists in Netatalk versions 2.2.1 to 4.4.2 due to improper error handling following a failed chdir() call. This issue could allow local privileged users to execute unintended commands or disrupt service functionality under certain conditions. It highlights the need for robust error management in command handling.

Affected Version(s)

Netatalk 2.2.1 <= 4.4.2

Netatalk 4.5.0

References

CVSS V3.1

Score:
2.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Basnet from Securin
.