Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-59260: OpenWrt luci-app-samba4 allows unauthorized code execution
CVE-2026-59260
CVE-2026-59260
Summary
The OpenWrt luci-app-samba4 software has a security issue that allows attackers to run unauthorized code on the system. This can happen when an attacker uses a valid login to gain access to the system and execute commands. To protect your system, update the OpenWrt luci-app-samba4 software to the latest version as soon as possible.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| openwrt | luci | All versions |
Original title
OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-line arguments. Att...
Original description
OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-line arguments. Attackers can pass arbitrary Samba global options such as message command to a root smbd process, triggering command execution when SMB protocol messages are processed.
nvd CVSS3.1
8.8
nvd CVSS4.0
8.7
Vulnerability type
CWE-269
Improper Privilege Management
Published: 12 Jul 2026 · Updated: 20 Jul 2026 · First seen: 12 Jul 2026