Improper Input Validation in Netatalk Affects Remote Data Modification
CVE-2026-7836

3.1LOW

Key Information:

Vendor

Netatalk

Status
Vendor
CVE Published:
21 May 2026

What is CVE-2026-7836?

An improper calculation within the hextoint macro in Netatalk versions 2.0.0 to 4.4.2 allows a remote authenticated attacker to manipulate data through specially crafted hexadecimal input. This flaw arises from the software’s inappropriate handling of uppercase characters, potentially leading to limited data alterations.

Affected Version(s)

Netatalk 2.0.0 <= 4.4.2

Netatalk 4.5.0

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Basnet from Securin
.