CVE-2026-4480

CRITICAL EXPLOITED NUCLEI

Samba: samba: remote code execution in printing subsystem via unescaped job description

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-4480 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 8 public exploits from researchers including CarlosEduardoPM, Cosm3No1de, ClearLotus-git. A Nuclei detection template is also available.

AI-analyzed exploit summary The repository contains a functional exploit for CVE-2026-4480, a command injection vulnerability in the Samba printing subsystem. The exploit leverages improper sanitization of the print job description to achieve remote code execution via the `%J` substitution parameter.

Description

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.

Exploits (8)

github WORKING POC 1 stars
by CarlosEduardoPM · pythonpoc
https://github.com/CarlosEduardoPM/CVE-2026-4480-POC

The repository contains a functional exploit for CVE-2026-4480, a command injection vulnerability in the Samba printing subsystem. The exploit leverages improper sanitization of the print job description to achieve remote code execution via the `%J` substitution parameter.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Samba (printing subsystem)
No auth needed
Prerequisites: Samba configured as a print server with `print command` using `%J` substitution · Network access to the Samba service
mistral-large-3 · analyzed Jun 09, 2026 Full analysis →
github WRITEUP
by Cosm3No1de · htmlpoc
https://github.com/Cosm3No1de/HTB-Abducted-Writeup

Technical writeup detailing the exploitation of CVE-2026-4480, a critical Samba printing subsystem vulnerability enabling remote code execution (RCE). The document provides a full attack chain, including SMB misconfigurations (wide links, force user), systemd abuse for privilege escalation, and SUID exploitation to achieve root access on a HackTheBox Linux machine.

Classification
Writeup 98%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Samba (printing subsystem, affected by CVE-2026-4480)
No auth needed
Prerequisites: Unauthenticated access to vulnerable Samba share (HP-Reception) · Valid PoC for CVE-2026-4480 · SMB misconfigurations (wide links = yes, force user) · Write permissions to systemd service directory for LPE
mistral-large-3 · analyzed Jul 06, 2026 Full analysis →
github WORKING POC
by ClearLotus-git · pythonremote
https://github.com/ClearLotus-git/CVE-2026-4480-PoC

The repository contains a functional Python exploit for CVE-2026-4480, a command injection vulnerability in Samba's print job handling. The exploit leverages the `%J` macro in print commands to execute arbitrary shell commands, including a reverse shell payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Samba (versions prior to 4.22.10, 4.23.8, 4.24.3)
No auth needed
Prerequisites: Samba with sysv-style printing configured · Guest printer share access · Print command using `%J` macro
mistral-large-3 · analyzed Jun 20, 2026 Full analysis →
github WORKING POC
by Vusal777 · pythonremote
https://github.com/Vusal777/CVE-2026-4480-exploit-poc

This repository contains a functional exploit for CVE-2026-4480, leveraging Samba's print spooler service to achieve remote command execution via crafted print job submissions. The exploit uses Samba's Python bindings to interact with the spoolss RPC interface and injects commands through the document name field.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Samba (version not specified)
No auth needed
Prerequisites: Access to Samba's SMB service (port 445) · Writable printer share · Optional: Valid credentials or anonymous access
mistral-large-3 · analyzed Jun 16, 2026 Full analysis →
github WORKING POC
by CarlosEduardoPM · pythonremote
https://github.com/CarlosEduardoPM/CVE-2026-4480

The repository contains a functional exploit for CVE-2026-4480, a command injection vulnerability in the Samba printing subsystem. The exploit leverages improper handling of the `%J` substitution parameter in print commands to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Samba (printing subsystem)
No auth needed
Prerequisites: Samba configured as a print server with `print command` using `%J` substitution · Network access to the Samba service
mistral-large-3 · analyzed Jun 08, 2026 Full analysis →
github WRITEUP
by 0xBlackash · poc
https://github.com/0xBlackash/CVE-2026-4480

This repository provides a detailed technical analysis of CVE-2026-4480, a critical command injection vulnerability in Samba's printing subsystem. It includes root cause analysis, affected versions, mitigation steps, and detection methods, but does not contain exploit code.

Classification
Writeup 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Samba (versions before 4.22.10, 4.23.8, 4.24.3)
No auth needed
Prerequisites: Samba configured with a custom print command using %J parameter · Network access to the Samba server
mistral-large-3 · analyzed Jun 08, 2026 Full analysis →
github WORKING POC
by robinxiang · pythonremote
https://github.com/robinxiang/CVE-2026-4480

This repository contains a functional exploit for CVE-2026-4480, targeting a Samba Print Command Injection vulnerability. The exploit leverages the spoolss RPC interface to inject commands via the printer job name, achieving remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Samba (specific version not specified)
No auth needed
Prerequisites: Network access to the target Samba service · Anonymous authentication enabled
mistral-large-3 · analyzed Jun 07, 2026 Full analysis →
github WORKING POC
by TheCyberGeek · pythonremote
https://github.com/TheCyberGeek/CVE-2026-4480-PoC

This repository contains a functional exploit for CVE-2026-4480, demonstrating unauthenticated remote command execution in Samba's print subsystem via shell injection through the `%J` macro in the print command. The exploit leverages Samba's Python bindings to submit a crafted print job that triggers command execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Samba (versions before 4.22.10, 4.23.8, 4.24.3)
No auth needed
Prerequisites: Samba Python bindings · Network access to SMB port (445/139) · Guest-accessible printer share with `%J` in print command
mistral-large-3 · analyzed Jun 05, 2026 Full analysis →

Nuclei Templates (1)

Samba Printing Subsystem - Remote Code Execution
CRITICALby projectdiscovery
Shodan: port:445 product:Samba
FOFA: protocol=smb && banner=Samba

References (15)

Core 15
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:22644
https://access.redhat.com/errata/RHSA-2026:22644
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:22963
https://access.redhat.com/errata/RHSA-2026:22963
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:25049
https://access.redhat.com/errata/RHSA-2026:25049
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:25979
https://access.redhat.com/errata/RHSA-2026:25979
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:28054
https://access.redhat.com/errata/RHSA-2026:28054
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:28055
https://access.redhat.com/errata/RHSA-2026:28055
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:28056
https://access.redhat.com/errata/RHSA-2026:28056
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:28057
https://access.redhat.com/errata/RHSA-2026:28057
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:28058
https://access.redhat.com/errata/RHSA-2026:28058
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:28053
https://access.redhat.com/errata/RHSA-2026:28053
Vdb Entry, X_Refsource_Redhat vdb-entry x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2026-4480
Issue Tracking, X_Refsource_Redhat issue-tracking x_refsource_redhat
RHBZ#2452232
https://bugzilla.redhat.com/show_bug.cgi?id=2452232
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:28132
https://access.redhat.com/errata/RHSA-2026:28132

Scores

CVSS v3 9.0
EPSS 0.1393
EPSS Percentile 96.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

VulnCheck KEV 2026-07-20
CWE
CWE-78
Status published
Products (26)
Red Hat/Red Hat Enterprise Linux 10
Red Hat/Red Hat Enterprise Linux 10 0:4.23.5-109.el10_2
Red Hat/Red Hat Enterprise Linux 10.0 Extended Update Support 0:4.21.3-114.el10_0.1
Red Hat/Red Hat Enterprise Linux 6
Red Hat/Red Hat Enterprise Linux 7
Red Hat/Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:4.10.16-26.el7_9.1
Red Hat/Red Hat Enterprise Linux 8
Red Hat/Red Hat Enterprise Linux 8 0:4.19.4-16.el8_10
Red Hat/Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 0:4.13.3-12.el8_4.1
Red Hat/Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On 0:4.13.3-12.el8_4.1
... and 16 more
Published May 26, 2026
Tracked Since May 26, 2026