CVE detail
CVE-2026-4480
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 27.7 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
15 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4480.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMay 26, 2026, 3:16 PM - https://bugzilla.samba.org/show_bug.cgi?id=16033bugzilla.samba.org
No excerpt available.
Vendor Advisorybugzilla.samba.orgMay 26, 2026, 3:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2452232bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMay 26, 2026, 3:16 PM - https://access.redhat.com/security/cve/CVE-2026-4480access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 26, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:28132access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 26, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:28058access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 26, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:28057access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 26, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:28056access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 26, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:28055access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 26, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:28054access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 26, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:28053access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 26, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:25979access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 26, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:25049access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 26, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:22963access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 26, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:22644access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 26, 2026, 3:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-4408CVSS 9.0 · Critical
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If t…
- CVE-2026-2340CVSS 6.5 · Medium
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable gr…
- CVE-2026-1933CVSS 7.1 · High
A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with under…
- CVE-2026-3012CVSS 8.0 · High
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted…
- CVE-2023-0118CVSS 9.1 · Critical
An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates and execute arbitrary code on the underlying operating syste…
- CVE-2023-34152CVSS 9.8 · Critical
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.