Junglewise Threat Intelligence

CVE-2026-2340: Samba vfs_worm file overwrite via rename operation

CVE-2026-2340 · Severity: medium · CVSS 6.5 · Published 2026-05-27

Technologies: Samba. Vendors: Samba.

Executive brief

A vulnerability in Samba's 'write-once, read-many' (WORM) module allows users to bypass data protection rules. This module is typically used to ensure that files cannot be modified or deleted after they are created, which is critical for compliance and data integrity. An authorized user can exploit this flaw to overwrite or delete protected files, potentially leading to the loss or unauthorized alteration of permanent records.

Technical details

A logic flaw exists in the Samba vfs_worm module due to insufficient validation during SMB rename operations. While the module is designed to prevent file modifications after a configurable grace period, the rename hook only validates the source path and fails to check the WORM status of the destination path. An authenticated attacker with write permissions to a share can exploit this by renaming a new, unprotected file over an existing WORM-protected file (using ReplaceIfExists=1), effectively bypassing immutability guarantees. The vulnerability affects Samba versions 4.21 and newer where vfs_worm is enabled. Patches have been released in versions 4.24.3, 4.23.8, and 4.22.10.

Affected products

  • Samba Samba 4.21, 4.22, 4.23, 4.24

Timeline

  • 2026-02-11: other: Vulnerability reported to Samba developers
  • 2026-05-26: patched: Samba releases 4.24.3, 4.23.8, and 4.22.10 containing the fix
  • 2026-05-27: disclosed: Public disclosure of CVE-2026-2340

References

Related threats