
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-58222 is a vulnerability in Samba related to improper handling of LDAP Compare requests, which can allow an authenticated user to obtain sensitive information. The CVE identifier is currently in "Reserved" status, and full technical details have not yet been publicly published. It affects multiple Ubuntu LTS releases running Samba, with patched package versions available for Ubuntu 22.04, 24.04, and 26.04 LTS. Feedly's estimate categorizes this as HIGH severity, though no official CVSS score has been published at this time (Ubuntu Advisory, Feedly).
According to available intelligence, CVE-2026-58222 combines LDAP Compare filter injection with a trusted search context bypass, allowing attackers to exploit Samba's search filters without proper validation of attribute names or escaping of assertion values. This is consistent with an improper neutralization or improper input validation weakness (likely CWE-20 or CWE-90 — LDAP injection). The vulnerability is triggered via authenticated LDAP Compare requests, meaning an attacker must have valid credentials to the Samba/AD domain to exploit it. No public proof-of-concept code or detailed technical write-up has been identified at this time (Ubuntu Advisory, Feedly).
Successful exploitation of CVE-2026-58222 could allow an authenticated attacker to obtain sensitive information from Samba's LDAP directory, potentially including user credentials, group memberships, or other directory objects. In an Active Directory domain context, this information disclosure could facilitate privilege escalation or lateral movement. The vulnerability is distinct from the more severe CVE-2026-58221 (domain takeover), but information obtained via this flaw could be leveraged to support further attacks (Ubuntu Advisory).
Ubuntu has released patched Samba package versions addressing CVE-2026-58222 as part of USN-8621-1. Affected users should update to the following versions: Ubuntu 26.04 LTS — samba 2:4.23.6+dfsg-1ubuntu2.2; Ubuntu 24.04 LTS — samba 2:4.19.5+dfsg-4ubuntu9.7; Ubuntu 22.04 LTS — samba 2:4.15.13+dfsg-0ubuntu1.13. A standard system update (apt upgrade) will apply the necessary changes. SUSE and openSUSE have also released security updates addressing this vulnerability (Ubuntu Advisory, SUSE Advisory, openSUSE).
The vulnerability was disclosed as part of a broader Samba security release in late July 2026 that addressed multiple critical flaws, including a domain takeover vulnerability (CVE-2026-58221). Community coverage noted that Samba patched "critical domain takeover flaws across all branches," with CVE-2026-58222 receiving less individual attention due to its lower severity relative to the domain takeover issue. Multiple Linux distributions including Ubuntu, SUSE, openSUSE, Slackware, and Debian issued coordinated security advisories (Linux Compatible, Ubuntu Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."