Junglewise Threat Intelligence

CVE-2026-44076: Netatalk shell injection in Spotlight volume path

CVE-2026-44076 · Severity: medium · CVSS 6.7 · Published 2026-05-21

Technologies: Netatalk. Vendors: Netatalk.

Executive brief

Netatalk is an open-source implementation of the Apple Filing Protocol (AFP) used to provide file services for Apple Macintosh computers. A security flaw in how the software handles storage volume paths could allow an administrator or a user with high-level system access to execute unauthorized commands on the server. While this requires existing high-level access to the configuration, it could lead to a full system takeover or persistent unauthorized access.

Technical details

A shell injection vulnerability (CWE-78) exists in Netatalk's Spotlight service setup. The root cause is the improper neutralization of administrator-configured volume paths when they are embedded into single-quoted shell commands. An attacker with high privileges (PR:H) who can influence the configuration files can inject arbitrary OS commands that execute when the service starts or reconfigures. The attack vector is local (AV:L), meaning it cannot be exploited remotely via the AFP protocol alone. The issue is fixed in version 4.4.3 or by applying a specific security patch to version 4.4.2.

Affected products

  • Netatalk Netatalk 3.1.0 through 4.4.2

Timeline

  • 2026-05-13: disclosed: Initial disclosure date
  • 2026-05-21: advisory: NVD publication date
  • 2026-05-21: patched: Fixed in version 4.4.3

References

Related threats