Executive brief
yast2-samba-client is a SUSE Linux tool for joining systems to Active Directory domains. An attacker who controls the Active Directory environment (such as a rogue domain controller or privileged directory user) can exploit improper command filtering to execute arbitrary commands with root privileges on machines being joined to the domain, leading to complete system compromise.
Technical details
The vulnerability is a command injection flaw (CWE-78) in yast2-samba-client that improperly neutralizes special shell metacharacters in OS commands. The vulnerable component processes Active Directory directory tree data during domain join operations. An attacker who controls the AD environment can inject malicious command syntax through directory objects they create or modify. No user interaction or additional authentication is required beyond the initial domain join attempt; the attacker's payload executes with root privileges during the join process. Patches are expected from SUSE for versions through 5.0.4.
Affected products
- SUSE yast2-samba-client through 5.0.4
Timeline
- 2026-09-01: disclosed