CVE-2026-58221
Samba vulnerability analysis and mitigation

Overview

CVE-2026-58221 is a vulnerability in Samba that allows authenticated users to perform unauthorized modifications to internal LDB special directory names via LDAP requests, potentially enabling domain takeover. The flaw affects Samba across multiple branches and was disclosed in late July 2026. Affected versions include those packaged in Ubuntu 22.04 LTS (before 2:4.15.13+dfsg-0ubuntu1.13), Ubuntu 24.04 LTS (before 2:4.19.5+dfsg-4ubuntu9.7), and Ubuntu 26.04 LTS (before 2:4.23.6+dfsg-1ubuntu2.2). The CVE is currently in Reserved status with no official CVSS score published, though Feedly estimates the severity as HIGH (Ubuntu Advisory, Feedly).

Technical details

The vulnerability stems from improper handling of internal LDB (LDAP-like Database) special directory names (DNs) when processing authenticated LDAP requests in Samba's Active Directory Domain Controller functionality. Low-privilege domain users can craft LDAP requests that modify these special DNs, which are normally protected system objects within the directory service. This maps to improper access control (CWE-284) or improper authorization (CWE-285), as the access control checks on these special objects are insufficient. The attack requires authenticated LDAP access to the domain, meaning the attacker must already possess valid domain credentials (Ubuntu Advisory, Linux Compatible).

Impact

Successful exploitation allows an authenticated but low-privileged domain user to perform unauthorized modifications to critical internal directory structures, potentially leading to full domain takeover. This could result in complete compromise of confidentiality, integrity, and availability of the Active Directory domain — including the ability to escalate privileges, impersonate domain administrators, and control all domain-joined systems. The scope of impact extends to all resources within the affected domain, making lateral movement and persistent access trivial once exploitation succeeds (Ubuntu Advisory, Linux Compatible).

Exploitation steps

  1. Obtain domain credentials: Acquire valid low-privilege domain user credentials through phishing, credential stuffing, or other means — no elevated privileges are required.
  2. Identify target: Locate a Samba-based Active Directory Domain Controller running a vulnerable version using network scanning tools (e.g., nmap with LDAP service detection).
  3. Authenticate to LDAP: Connect to the domain controller's LDAP service (port 389 or 636 for LDAPS) using the obtained credentials and a standard LDAP client (e.g., ldapsearch, ldapmodify, or Python's ldap3 library).
  4. Identify special LDB DNs: Enumerate internal LDB special directory names that are normally restricted, such as those controlling domain replication, schema, or configuration partitions.
  5. Craft malicious LDAP modification request: Send a crafted LDAP modify request targeting the identified special DNs to make unauthorized changes — such as modifying ACLs, adding privileged accounts, or altering domain configuration objects.
  6. Achieve domain takeover: Leverage the unauthorized modifications to escalate privileges, add a rogue domain administrator account, or otherwise gain control of the domain (Ubuntu Advisory, Linux Compatible).

Indicators of compromise

  • Network: Unusual LDAP modify (LDAP opcode 6) requests from low-privilege user accounts targeting special or system-reserved DNs (e.g., CN=Schema, CN=Configuration, or domain root objects); LDAP traffic on port 389/636 from unexpected source hosts.
  • Logs: Samba audit logs (smbd or winbindd) showing LDAP modification operations on protected directory objects by non-administrative accounts; unexpected changes to domain ACLs or schema objects in directory service event logs.
  • File System: Unexpected modifications to Samba's LDB database files (e.g., sam.ldb, secrets.ldb) with timestamps inconsistent with normal administrative activity.
  • Process: Unusual ldbmodify or samba-tool process invocations under non-root or non-admin user contexts; unexpected new privileged accounts appearing in the domain directory.

Mitigation and workarounds

Samba has released patched versions addressing this vulnerability. Ubuntu users should update to the following package versions: Ubuntu 26.04 LTS → samba 2:4.23.6+dfsg-1ubuntu2.2, Ubuntu 24.04 LTS → samba 2:4.19.5+dfsg-4ubuntu9.7, Ubuntu 22.04 LTS → samba 2:4.15.13+dfsg-0ubuntu1.13. SUSE and openSUSE users should apply the updates referenced in SUSE-SU-2026:3363-1 and the corresponding openSUSE security announcements. A standard system update is the recommended remediation; no specific configuration-based workaround has been publicly documented. Organizations should prioritize patching Samba-based domain controllers immediately given the domain takeover potential (Ubuntu Advisory, SUSE Advisory, openSUSE).

Community reactions

The vulnerability was highlighted in a Linux Compatible report titled "Samba patches critical domain takeover flaws across all branches," indicating broad community recognition of the severity. Multiple Linux distributions — including Ubuntu, SUSE, openSUSE, Slackware, and Debian — rapidly issued security advisories and updated packages, reflecting coordinated vendor response. The oss-security mailing list also carried a disclosure thread (oss-sec/2026/q3/317), suggesting standard responsible disclosure practices were followed (Linux Compatible, oss-sec).

Additional resources


SourceThis report was generated using AI

Related Samba vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-6949NONEN/A
  • Samba logoSamba
  • samba-libs-32bit
NoYesJul 28, 2026
CVE-2026-58224NONEN/A
  • Samba logoSamba
  • samba-winbind-libs
NoYesJul 28, 2026
CVE-2026-58222NONEN/A
  • Samba logoSamba
  • samba-libs-32bit
NoYesJul 28, 2026
CVE-2026-58221NONEN/A
  • Samba logoSamba
  • libldb2
NoYesJul 28, 2026
CVE-2026-58218NONEN/A
  • Samba logoSamba
  • samba-gpupdate
NoYesJul 28, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management