LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-58222

Published
CVSS8.8
Severityhigh
WeaknessCWE-90
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to properly validate user-supplied attribute names and executes the resulting internal database search in a trusted context, bypassing normal Access Control List (ACL) enforcement. An authenticated low-privilege domain user can exploit these flaws to disclose confidential Active Directory attributes that would normally be inaccessible. The disclosed information may be leveraged to derive sensitive authentication material, potentially leading to privilege escalation and complete domain compromise. Fo

References

← Back to the CVE Tracker

Our coverage of CVE-2026-58222

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-58222.