Junglewise Threat Intelligence

CVE-2026-3012: Samba certificate auto-enrollment improper validation in Group Policy

CVE-2026-3012 · Severity: high · CVSS 8 · Published 2026-05-27

Technologies: Samba. Vendors: Samba.

Executive brief

A vulnerability in Samba's certificate auto-enrollment feature could allow an attacker on the same network to intercept or spoof secure communications. When a Linux computer joins a Windows domain, Samba may download security certificates over an unencrypted connection without verifying them. This allows an attacker to install a malicious certificate authority on the system, potentially gaining persistent access to encrypted data or impersonating trusted services.

Technical details

A vulnerability exists in the Samba Group Policy certificate auto-enrollment extension (`gp_cert_auto_enroll_ext.py`). When processing certificate enrollment, the component fetches a Certificate Authority (CA) certificate via SCEP over plain HTTP and installs it into the system-wide trust store (e.g., `/usr/local/share/ca-certificates/`) without validating it against the trusted `cACertificate` already obtained via Kerberos-authenticated LDAP. An attacker capable of intercepting or redirecting network traffic (Machine-in-the-Middle) can provide a rogue CA certificate. This rogue certificate is then trusted by the system, allowing the attacker to intercept or spoof TLS traffic. The issue affects Samba versions 4.1 and newer when Group Policy is enabled. Patches have been developed to prioritize LDAP-provided certificates or enforce validation.

Affected products

  • Samba Samba 4.1 and newer

Timeline

  • 2026-02-17: disclosed: Reported to Samba by DREAM Security Research Team
  • 2026-05-27: advisory: Public disclosure of CVE-2026-3012

References

Related threats