CVE-2026-4408Redhat · Openshift_container_platform
Vulnerability data via NVD (ingested)
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-4408product:"Redhat Openshift Container Platform" version:"4.0"http.html:"Openshift Container Platform"More intel sources (5)
vuln:CVE-2026-4408vulnerabilities.cve_id: CVE-2026-4408CVE-2026-4408CVE-2026-4408"CVE-2026-4408" exploit -site:nvd.nist.gov