CVE detail
CVE-2026-1933
A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations even on read-only exports. This could allow modification of SMB-visible file behavior, including converting files into symbolic links or other reparse point types.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 27.1 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
14 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1933.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMay 27, 2026, 2:16 PM - https://bugzilla.samba.org/show_bug.cgi?id=15992bugzilla.samba.org
No excerpt available.
Vendor Advisorybugzilla.samba.orgMay 27, 2026, 2:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2447317bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMay 27, 2026, 2:16 PM - https://access.redhat.com/security/cve/CVE-2026-1933access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 27, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:29863access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 27, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:28057access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 27, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:28056access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 27, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:28055access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 27, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:28054access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 27, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:28053access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 27, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:25979access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 27, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:25049access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 27, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:22963access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 27, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:22644access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 27, 2026, 2:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-4408CVSS 9.0 · Critical
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If t…
- CVE-2026-2340CVSS 6.5 · Medium
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable gr…
- CVE-2026-3012CVSS 8.0 · High
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted…
- CVE-2026-4480CVSS 9.0 · Critical
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J"…
- CVE-2021-3864CVSS 7.0 · High
A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal t…
- CVE-2019-10200CVSS 7.2 · High
A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloads on master nodes. Pods with…