LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-3012

redhat · openshift container platform

Published
CVSS8
Severityhigh
WeaknessCWE-345
ExploitedNot in CISA KEV

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

Description

A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-3012

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-3012.