CVE-2010-0926

Samba <3.3.11, <3.4.6, <3.5.0rc3 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2010-0926. PoCs published by kingcope, kcope, hdm, including Metasploit module auxiliary/admin/smb/samba_symlink_traversal.

AI-analyzed exploit summary This exploit leverages a directory traversal vulnerability in Samba by creating a symlink in a writable share to access the root filesystem. It requires authenticated access to a writable share, which could be accessible via guest accounts.

Description

The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, and access arbitrary files, by using the symlink command in smbclient to create a symlink containing .. (dot dot) sequences, related to the combination of the unix extensions and wide links options.

Exploits (3)

exploitdb WORKING POC VERIFIED
by kingcope · rubyremotelinux
https://www.exploit-db.com/exploits/33598

This exploit leverages a directory traversal vulnerability in Samba by creating a symlink in a writable share to access the root filesystem. It requires authenticated access to a writable share, which could be accessible via guest accounts.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Samba (versions with 'wide links = yes' default configuration)
Auth required
Prerequisites: Authenticated access to a writable Samba share · Samba configured with 'wide links = yes'
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by kingcope · textremotelinux
https://www.exploit-db.com/exploits/33599

This exploit leverages a directory traversal vulnerability in Samba by modifying the symlink command to bypass path sanitization. It allows authenticated users to create symlinks outside the intended directory, potentially leading to unauthorized file access.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Samba 3.4.5
Auth required
Prerequisites: Authenticated access to a writable Samba share · Samba configured with 'wide links = yes' (default in vulnerable versions)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC
by kcope, hdm · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/smb/samba_symlink_traversal.rb

This Metasploit module exploits a directory traversal vulnerability in Samba (CVE-2010-0926) by creating a symlink in a writable share that points to the root filesystem. It allows an attacker to access arbitrary files on the server by traversing directories via the SMB protocol.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Samba versions prior to 3.5.5
Auth required
Prerequisites: A writable SMB share on the target server · Valid SMB credentials for authentication
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (35)

Core 35
Core References
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=samba-technical&m=126555346721629&w=2
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=samba-technical&m=126549111204428&w=2
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=samba-technical&m=126540539117328&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39317
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2010/02/06/3
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=samba-technical&m=126540376915283&w=2
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2010/03/05/3
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=samba-technical&m=126540477016522&w=2
Third Party Advisory mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2010-02/0107.html
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=samba-technical&m=126540248613395&w=2
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=samba-technical&m=126540290614053&w=2
Mailing List mailing-list x_refsource_fulldisc
http://marc.info/?l=full-disclosure&m=126538598820903&w=2
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=samba-technical&m=126548356728379&w=2
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=oss-security&m=126545363428745&w=2
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=samba-technical&m=126540475116511&w=2
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=samba-technical&m=126539387432412&w=2
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=samba-technical&m=126540695819735&w=2
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=oss-security&m=126777580624790&w=2
Third Party Advisory mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2010-02/0083.html
Vendor Advisory x_refsource_confirm
http://www.samba.org/samba/news/symlink_attack.html
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=samba-technical&m=126547903723628&w=2
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=samba-technical&m=126540011609753&w=2
Issue Tracking x_refsource_confirm
https://bugzilla.samba.org/show_bug.cgi?id=7104
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=oss-security&m=126539592603079&w=2
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=oss-security&m=126540733320471&w=2
Third Party Advisory mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2010-02/0108.html
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=samba-technical&m=126540608318301&w=2
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=samba-technical&m=126540100511357&w=2
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=samba-technical&m=126540277713815&w=2
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=oss-security&m=126540402215620&w=2
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=562568

Scores

EPSS 0.5631
EPSS Percentile 98.2%

Details

CWE
CWE-22
Status published
Products (18)
samba/samba 3.3.0
samba/samba 3.3.1
samba/samba 3.3.2
samba/samba 3.3.3
samba/samba 3.3.4
samba/samba 3.3.5
samba/samba 3.3.6
samba/samba 3.3.7
samba/samba 3.3.8
samba/samba 3.3.9
... and 8 more
Published Mar 10, 2010
Tracked Since Feb 18, 2026