Samba Product Security Update Advisory (CVE-2026-58222)

Samba Product Security Update Advisory (CVE-2026-58222)

Overview

A vulnerability, CVE-2026-58222, has been identified in the Samba product, and a security update addressing this issue has been released. This vulnerability is an issue in Samba AD DC (Samba’s Active Directory Domain Controller) where LDAP Compare filter injection and errors in handling trust requests could lead to the exposure of confidential attribute information.

Affected Systems

  • Samba AD DC version 4.0.0 And later are affected.

Recommended Actions

  • A security patch is available via the latest security update.
  • You must update to the following versions according to the provided instructions.
    • Samba 4.22.11
    • Samba 4.23.10
    • Samba 4.24.5

Reference

  • Guidance regarding CVE-2026-58222 has been posted in the Samba security advisory.