LDAP Filter Injection Vulnerability in Samba Active Directory Domain Controller
CVE-2026-58222

8.8HIGH

What is CVE-2026-58222?

A security vulnerability exists in Samba Active Directory Domain Controller that combines LDAP filter injection and improper authorization checks. This flaw arises when processing LDAP Compare requests and allows Samba to inadequately validate user-supplied attribute names. Consequently, it executes internal database searches in a trusted context, circumventing standard Access Control List (ACL) protections. An authenticated user with low privileges can exploit these weaknesses to reveal private Active Directory attributes that are otherwise restricted. Such disclosures may provide attackers with sensitive authentication details, increasing the risk of privilege escalation and complete compromise of the domain. Especially in configurations utilizing Group Managed Service Accounts (gMSAs), attackers can extract the 'msKds-RootKeyData' attribute, enabling them to potentially derive gMSA passwords offline, which could lead to a total domain breach if privileged gMSAs are involved.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Andrew Tridgell (Samba Team), Bin Luo (University of Electronic Science and Technology of China (UESTC)), OpenAI Security Research, and Tristan Madani (Talence Security) for reporting this issue.
.