Samba: group policy certificate enrollment uses http:// without validation
Published May 27, 2026
8.0
HIGHCVSS 3.1
EPSS 0.23%
Description
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 7 | affected |
| |||
| Red Hat | Red Hat OpenShift Container Platform 4 | affected |
|
- 4.0
- ≥ 4.16.0 · < 4.21.0
- 7.0
- 9.0
No data.
Red Hat Enterprise Linux 10
samba-0:4.23.5-109.el10_2
Fixed · RHSA-2026:22963
Red Hat Enterprise Linux 10.0 Extended Update Support
samba-0:4.21.3-114.el10_0.1
Fixed · RHSA-2026:28055
Red Hat Enterprise Linux 8
samba-0:4.19.4-16.el8_10
Fixed · RHSA-2026:22644
Red Hat Enterprise Linux 8
samba-0:4.19.4-16.el8_10
Fixed · RHSA-2026:22644
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
samba-0:4.15.5-16.el8_6.1
Fixed · RHSA-2026:28057
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
samba-0:4.15.5-16.el8_6.1
Fixed · RHSA-2026:28057
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
samba-0:4.17.5-7.el8_8.1
Fixed · RHSA-2026:28056
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
samba-0:4.17.5-7.el8_8.1
Fixed · RHSA-2026:28056
Red Hat Enterprise Linux 9
samba-0:4.23.5-10.el9_8
Fixed · RHSA-2026:25049
Red Hat Enterprise Linux 9
samba-0:4.23.5-10.el9_8
Fixed · RHSA-2026:25049
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
samba-0:4.17.5-105.el9_2.5
Fixed · RHSA-2026:28054
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
samba-0:4.19.4-105.el9_4.4
Fixed · RHSA-2026:28053
Red Hat Enterprise Linux 9.6 Extended Update Support
samba-0:4.21.3-14.el9_6.1
Fixed · RHSA-2026:25979
Red Hat OpenShift Container Platform 4.12
rhcos-412.86.202608241157-0
Fixed · RHSA-2026:59831
Red Hat OpenShift Container Platform 4.12
rhcos-412.86.202609082051-0
Fixed · RHSA-2026:65907
Red Hat OpenShift Container Platform 4.13
rhcos-413.92.202609080414-0
Fixed · RHSA-2026:65839
Red Hat OpenShift Container Platform 4.14
rhcos-414.92.202608172040-0
Fixed · RHSA-2026:56786
Red Hat OpenShift Container Platform 4.14
rhcos-414.92.202609011250-0
Fixed · RHSA-2026:62409
Red Hat OpenShift Container Platform 4.15
rhcos-415.92.202608180329-0
Fixed · RHSA-2026:56911
Red Hat OpenShift Container Platform 4.16
rhcos-416.94.202608150307-0
Fixed · RHSA-2026:56853
Red Hat OpenShift Container Platform 4.16
rhcos-416.94.202609011112-0
Fixed · RHSA-2026:62549
Red Hat OpenShift Container Platform 4.17
rhcos-417.94.202608250221-0
Fixed · RHSA-2026:60019
Red Hat OpenShift Container Platform 4.18
rhcos-418.94.202608142238-0
Fixed · RHSA-2026:57483
Red Hat OpenShift Container Platform 4.18
rhcos-418.94.202609031320-0
Fixed · RHSA-2026:65851
Red Hat OpenShift Container Platform 4.19
rhcos-4.19.9.6.202606241344-0
Fixed · RHSA-2026:29863
Red Hat Enterprise Linux 6
samba
Out of support scope
Red Hat Enterprise Linux 6
samba4
Out of support scope
Red Hat Enterprise Linux 7
samba
Will not fix
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | samba-0:4.23.5-109.el10_2 | Fixed | RHSA-2026:22963 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | samba-0:4.21.3-114.el10_0.1 | Fixed | RHSA-2026:28055 |
| Red Hat Enterprise Linux 8 | samba-0:4.19.4-16.el8_10 | Fixed | RHSA-2026:22644 |
| Red Hat Enterprise Linux 8 | samba-0:4.19.4-16.el8_10 | Fixed | RHSA-2026:22644 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | samba-0:4.15.5-16.el8_6.1 | Fixed | RHSA-2026:28057 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | samba-0:4.15.5-16.el8_6.1 | Fixed | RHSA-2026:28057 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | samba-0:4.17.5-7.el8_8.1 | Fixed | RHSA-2026:28056 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | samba-0:4.17.5-7.el8_8.1 | Fixed | RHSA-2026:28056 |
| Red Hat Enterprise Linux 9 | samba-0:4.23.5-10.el9_8 | Fixed | RHSA-2026:25049 |
| Red Hat Enterprise Linux 9 | samba-0:4.23.5-10.el9_8 | Fixed | RHSA-2026:25049 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | samba-0:4.17.5-105.el9_2.5 | Fixed | RHSA-2026:28054 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | samba-0:4.19.4-105.el9_4.4 | Fixed | RHSA-2026:28053 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | samba-0:4.21.3-14.el9_6.1 | Fixed | RHSA-2026:25979 |
| Red Hat OpenShift Container Platform 4.12 | rhcos-412.86.202608241157-0 | Fixed | RHSA-2026:59831 |
| Red Hat OpenShift Container Platform 4.12 | rhcos-412.86.202609082051-0 | Fixed | RHSA-2026:65907 |
| Red Hat OpenShift Container Platform 4.13 | rhcos-413.92.202609080414-0 | Fixed | RHSA-2026:65839 |
| Red Hat OpenShift Container Platform 4.14 | rhcos-414.92.202608172040-0 | Fixed | RHSA-2026:56786 |
| Red Hat OpenShift Container Platform 4.14 | rhcos-414.92.202609011250-0 | Fixed | RHSA-2026:62409 |
| Red Hat OpenShift Container Platform 4.15 | rhcos-415.92.202608180329-0 | Fixed | RHSA-2026:56911 |
| Red Hat OpenShift Container Platform 4.16 | rhcos-416.94.202608150307-0 | Fixed | RHSA-2026:56853 |
| Red Hat OpenShift Container Platform 4.16 | rhcos-416.94.202609011112-0 | Fixed | RHSA-2026:62549 |
| Red Hat OpenShift Container Platform 4.17 | rhcos-417.94.202608250221-0 | Fixed | RHSA-2026:60019 |
| Red Hat OpenShift Container Platform 4.18 | rhcos-418.94.202608142238-0 | Fixed | RHSA-2026:57483 |
| Red Hat OpenShift Container Platform 4.18 | rhcos-418.94.202609031320-0 | Fixed | RHSA-2026:65851 |
| Red Hat OpenShift Container Platform 4.19 | rhcos-4.19.9.6.202606241344-0 | Fixed | RHSA-2026:29863 |
| Red Hat Enterprise Linux 6 | samba | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | samba4 | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | samba | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Systems are not affected unless Samba Group Policy processing and certificate auto-enrollment are explicitly enabled.
Administrators can reduce exposure by:
Avoiding unnecessary use of certificate auto-enrollment. Ensuring your "smb.conf" does not contain a line like ```apply group policies = yes```. If , group policy is not be enabled, the vulnerable code will not run.
Intercepting the HTTP request requires some control over the local network or other devices to intercept or redirect traffic. Some network administrators might assess this as a low risk on their networks.
Red Hat statement
Red Hat Product Security has rated this vulnerability as Important severity. However, exploitation requires several specific non-default conditions to be met. The vulnerable code path is only reachable when Samba Group Policy processing is explicitly enabled using the ```apply group policies = yes``` configuration option and certificate auto-enrollment is configured through Group Policy. Hence, although the vulnerable code is present, it is not exploitable in default RHEL configurations. In addition, the attacker must have the ability to intercept or redirect adjacent-network HTTP traffic during certificate retrieval. Because exploitation depends on explicit administrative configuration changes and adjacent-network positioning, Red Hat assesses the attack complexity as High (AC:H).
Red Hat mitigation
Systems are not affected unless Samba Group Policy processing and certificate auto-enrollment are explicitly enabled. Administrators can reduce exposure by: Avoiding unnecessary use of certificate auto-enrollment. Ensuring your "smb.conf" does not contain a line like ```apply group policies = yes```. If , group policy is not be enabled, the vulnerable code will not run. Intercepting the HTTP request requires some control over the local network or other devices to intercept or redirect traffic. Some network administrators might assess this as a low risk on their networks.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
1 other source (Red Hat) ▾
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed May 27, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
May–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.23% (0.00227) | 12.21th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.19% (0.00186) | 8.35th | v5 (v2026.06.15) |
| May 27, 2026 | 0.00% (0.00004) | 0.18th | v4 (v2025.03.14) |
References (29)
- https://access.redhat.com/errata/RHSA-2026:22644 vendor-advisoryx_refsource_REDHATIssue Tracking
- https://access.redhat.com/errata/RHSA-2026:22963 vendor-advisoryx_refsource_REDHATIssue Tracking
- https://access.redhat.com/errata/RHSA-2026:25049 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:25979 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:28053 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:28054 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:28055 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:28056 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:28057 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:29863 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:56786 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:56853 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:56911 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:57483 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:59831 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:60019 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:62409 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:62549 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:65839 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:65851 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:65907 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:67857 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:70586 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-3012 vdb-entryx_refsource_REDHATMitigationThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2447319 issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://bugzilla.samba.org/show_bug.cgi?id=16003 Issue TrackingMitigationVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-3012
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3012.json
- https://www.cve.org/CVERecord?id=CVE-2026-3012
Change history (0)
No recorded changes yet.