LDAP Filter Injection Vulnerability in Samba Active Directory Domain Controller
CVE-2026-58222
What is CVE-2026-58222?
A security vulnerability exists in Samba Active Directory Domain Controller that combines LDAP filter injection and improper authorization checks. This flaw arises when processing LDAP Compare requests and allows Samba to inadequately validate user-supplied attribute names. Consequently, it executes internal database searches in a trusted context, circumventing standard Access Control List (ACL) protections. An authenticated user with low privileges can exploit these weaknesses to reveal private Active Directory attributes that are otherwise restricted. Such disclosures may provide attackers with sensitive authentication details, increasing the risk of privilege escalation and complete compromise of the domain. Especially in configurations utilizing Group Managed Service Accounts (gMSAs), attackers can extract the 'msKds-RootKeyData' attribute, enabling them to potentially derive gMSA passwords offline, which could lead to a total domain breach if privileged gMSAs are involved.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved