Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2026-59260: OpenWrt luci-app-samba4 allows unauthorized code execution

CVE-2026-59260 CVE-2026-59260
Summary

The OpenWrt luci-app-samba4 software has a security issue that allows attackers to run unauthorized code on the system. This can happen when an attacker uses a valid login to gain access to the system and execute commands. To protect your system, update the OpenWrt luci-app-samba4 software to the latest version as soon as possible.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
openwrt luci All versions
Original title
OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-line arguments. Att...
Original description
OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-line arguments. Attackers can pass arbitrary Samba global options such as message command to a root smbd process, triggering command execution when SMB protocol messages are processed.
nvd CVSS3.1 8.8
nvd CVSS4.0 8.7
Vulnerability type
CWE-269 Improper Privilege Management
Published: 12 Jul 2026 · Updated: 20 Jul 2026 · First seen: 12 Jul 2026