Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-19349: Debian Linux: Unauthenticated Remote Code Execution in Samba

CVE-2026-19349 · published 18 days ago
Summary

A critical vulnerability in Debian's Samba package allows attackers to execute malicious code on a system without needing a password. This affects any Debian system running Samba, which is used for file sharing and authentication. To protect your system, update to the latest version of Samba or disable Samba services if not in use.

What to do
  • Update debian lemonldap-ng to version 2.0.11+ds-4+deb11u9.
  • Update debian lemonldap-ng to version 2.16.1+ds-deb12u9.
  • Update debian lemonldap-ng to version 2.21.2+ds-1+deb13u3.
Affected software
Ecosystem VendorProductAffected versions
Debian:11 debian lemonldap-ng < 2.0.11+ds-4+deb11u9
Fix: upgrade to 2.0.11+ds-4+deb11u9
Debian:12 debian lemonldap-ng < 2.16.1+ds-deb12u9
Fix: upgrade to 2.16.1+ds-deb12u9
Debian:13 debian lemonldap-ng < 2.21.2+ds-1+deb13u3
Fix: upgrade to 2.21.2+ds-1+deb13u3
Debian:14 debian lemonldap-ng All versions
Original advisory text
Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO ses...
Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends. Before redirecting to the identity provider, extractFormInfo() creates the state session with the positional call `getApacheSession( undef, 1, 0, 'GitHubState' )`. getApacheSession() takes a session id followed by a named argument hash, so the trailing arguments become that hash, `kind` defaults to SSO, and the state is written to the global session storage as a regular SSO session. Its identifier is handed to the unauthenticated visitor as the state parameter of the redirection URL. Any visitor who reaches the GitHub or LinkedIn endpoint can replay that identifier as a session cookie and obtain a valid SSO session without authenticating. The session holds neither _user nor authenticationLevel, which the shipped bootstrap configuration accepts because it grants virtual hosts a "default => accept" access rule; deployments whose rules test the user or require an authentication level are less exposed. Only configurations with the GitHub or LinkedIn authentication module enabled are affected.
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-305Authentication Bypass by Primary Weakness
CWE-628Function Call with Incorrectly Specified Arguments
Timeline
Published16 Aug 2026
Updated3 Sep 2026
First seen11 Aug 2026
Sources
CVE-2026-19349 · MITRE
Monitor software like this
Free during beta