CVE-2026-3012
HIGHSamba: group policy certificate enrollment uses http:// without validation
Title source: cnaDescription
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.
References (14)
Core 14
Core References
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:22963
https://access.redhat.com/errata/RHSA-2026:22963
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:22644
https://access.redhat.com/errata/RHSA-2026:22644
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:25049
https://access.redhat.com/errata/RHSA-2026:25049
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:25979
https://access.redhat.com/errata/RHSA-2026:25979
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:28053
https://access.redhat.com/errata/RHSA-2026:28053
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:28054
https://access.redhat.com/errata/RHSA-2026:28054
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:28055
https://access.redhat.com/errata/RHSA-2026:28055
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:28056
https://access.redhat.com/errata/RHSA-2026:28056
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:28057
https://access.redhat.com/errata/RHSA-2026:28057
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:29863
https://access.redhat.com/errata/RHSA-2026:29863
Vdb Entry, X_Refsource_Redhat vdb-entry
x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2026-3012
Issue Tracking, X_Refsource_Redhat issue-tracking
x_refsource_redhat
RHBZ#2447319
https://bugzilla.redhat.com/show_bug.cgi?id=2447319
Scores
CVSS v3
8.0
EPSS
0.0026
EPSS Percentile
17.8%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-345
Status
published
Products (22)
Red Hat/Red Hat Enterprise Linux 10
Red Hat/Red Hat Enterprise Linux 10
0:4.23.5-109.el10_2
Red Hat/Red Hat Enterprise Linux 10.0 Extended Update Support
0:4.21.3-114.el10_0.1
Red Hat/Red Hat Enterprise Linux 6
Red Hat/Red Hat Enterprise Linux 7
Red Hat/Red Hat Enterprise Linux 8
Red Hat/Red Hat Enterprise Linux 8
0:4.19.4-16.el8_10
Red Hat/Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
0:4.15.5-16.el8_6.1
Red Hat/Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
0:4.15.5-16.el8_6.1
Red Hat/Red Hat Enterprise Linux 8.8 Telecommunications Update Service
0:4.17.5-7.el8_8.1
... and 12 more
Published
May 27, 2026
Tracked Since
May 27, 2026