
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-58221 is a vulnerability in Samba that allows authenticated users to perform unauthorized modifications to internal LDB special directory names via LDAP requests, potentially enabling domain takeover. The flaw affects Samba across multiple branches and was disclosed in late July 2026. Affected versions include those packaged in Ubuntu 22.04 LTS (before 2:4.15.13+dfsg-0ubuntu1.13), Ubuntu 24.04 LTS (before 2:4.19.5+dfsg-4ubuntu9.7), and Ubuntu 26.04 LTS (before 2:4.23.6+dfsg-1ubuntu2.2). The CVE is currently in Reserved status with no official CVSS score published, though Feedly estimates the severity as HIGH (Ubuntu Advisory, Feedly).
The vulnerability stems from improper handling of internal LDB (LDAP-like Database) special directory names (DNs) when processing authenticated LDAP requests in Samba's Active Directory Domain Controller functionality. Low-privilege domain users can craft LDAP requests that modify these special DNs, which are normally protected system objects within the directory service. This maps to improper access control (CWE-284) or improper authorization (CWE-285), as the access control checks on these special objects are insufficient. The attack requires authenticated LDAP access to the domain, meaning the attacker must already possess valid domain credentials (Ubuntu Advisory, Linux Compatible).
Successful exploitation allows an authenticated but low-privileged domain user to perform unauthorized modifications to critical internal directory structures, potentially leading to full domain takeover. This could result in complete compromise of confidentiality, integrity, and availability of the Active Directory domain — including the ability to escalate privileges, impersonate domain administrators, and control all domain-joined systems. The scope of impact extends to all resources within the affected domain, making lateral movement and persistent access trivial once exploitation succeeds (Ubuntu Advisory, Linux Compatible).
ldapsearch, ldapmodify, or Python's ldap3 library).smbd or winbindd) showing LDAP modification operations on protected directory objects by non-administrative accounts; unexpected changes to domain ACLs or schema objects in directory service event logs.sam.ldb, secrets.ldb) with timestamps inconsistent with normal administrative activity.ldbmodify or samba-tool process invocations under non-root or non-admin user contexts; unexpected new privileged accounts appearing in the domain directory.Samba has released patched versions addressing this vulnerability. Ubuntu users should update to the following package versions: Ubuntu 26.04 LTS → samba 2:4.23.6+dfsg-1ubuntu2.2, Ubuntu 24.04 LTS → samba 2:4.19.5+dfsg-4ubuntu9.7, Ubuntu 22.04 LTS → samba 2:4.15.13+dfsg-0ubuntu1.13. SUSE and openSUSE users should apply the updates referenced in SUSE-SU-2026:3363-1 and the corresponding openSUSE security announcements. A standard system update is the recommended remediation; no specific configuration-based workaround has been publicly documented. Organizations should prioritize patching Samba-based domain controllers immediately given the domain takeover potential (Ubuntu Advisory, SUSE Advisory, openSUSE).
The vulnerability was highlighted in a Linux Compatible report titled "Samba patches critical domain takeover flaws across all branches," indicating broad community recognition of the severity. Multiple Linux distributions — including Ubuntu, SUSE, openSUSE, Slackware, and Debian — rapidly issued security advisories and updated packages, reflecting coordinated vendor response. The oss-security mailing list also carried a disclosure thread (oss-sec/2026/q3/317), suggesting standard responsible disclosure practices were followed (Linux Compatible, oss-sec).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."