← Back

CVE-2026-2340

nvd nist
Published: May 27, 2026Modified: Jul 2, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: secalert@redhat.com (Secondary)

Description

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.

Affected (6)

2 products
Enterprise Linux
Openshift Container Platform
1 product
Samba
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 10.0
Version 7.0
Version 8.0
Version 9.0
Version 4.0
From 4.1.0

References (13)

Source: secalert@redhat.com
MitigationThird Party Advisory
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
Issue TrackingVendor Advisory

Timeline

No history available yet.