Description
Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who controls the content of an Active Directory directory tree - a rogue domain controller, or a directory user delegated the right to create objects - to execute arbitrary commands as root on a machine being joined to that domain.
This issue affects yast2-samba-client through 5.0.4.
Published: 2026-09-01
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An OS command injection flaw in yast2-samba-client allows a malicious actor who can control entries in an Active Directory tree—such as a rogue domain controller or a delegated user—to insert arbitrary characters into an Organizational Unit field. When a machine is joined to the domain, the invalidated value is passed to a system command, giving the attacker the ability to execute commands with root privileges on that host. This flaw is classified as CWE-78.

Affected Systems

SUSE yast2-samba-client version 5.0.4 and earlier are vulnerable. Any system that uses yast2-samba-client to join a domain is at risk if the underlying AD structure can be manipulated by an attacker.

Risk and Exploitability

The CVSS score of 7.5 indicates a high impact. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it is not currently known to be exploited in the wild. The attack requires the ability to inject content into the AD directory, typically through a rogue domain controller or a user with privileges to create objects. Once such content is injected, the domain-joining process can be co-opted to run arbitrary commands as root on the target machine.

Generated by OpenCVE AI on September 1, 2026 at 11:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade yast2-samba-client to the latest released version that includes the fix for CVE‑2026‑25706.
  • If an immediate upgrade is not possible, restrict or monitor the ability to create or modify Organizational Units in Active Directory, ensuring only trusted administrators can perform such actions.
  • After ensuring the vulnerability is mitigated, verify that any domain controllers or delegated users cannot influence the directory tree used during the join process.

Generated by OpenCVE AI on September 1, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who controls the content of an Active Directory directory tree - a rogue domain controller, or a directory user delegated the right to create objects - to execute arbitrary commands as root on a machine being joined to that domain. This issue affects yast2-samba-client through 5.0.4.
Title yast2-samba-client: OS command injection via attacker-controlled Organizational Unit (Active Directory-supplied)
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2026-09-01T12:20:37.381Z

Reserved: 2026-02-05T15:37:24.184Z

Link: CVE-2026-25706

cve-icon Vulnrichment

Updated: 2026-09-01T12:20:29.623Z

cve-icon NVD

Status : Received

Published: 2026-09-01T10:17:12.993

Modified: 2026-09-01T13:18:32.350

Link: CVE-2026-25706

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T11:30:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')