Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-88880.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-88880
Upstream
Published
2026-05-26T15:16:40Z
Modified
2026-08-30T05:24:52Z
Summary
CVE-2026-4480 affecting package samba 4.18.3-2
Details

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.

References

Affected packages

Azure Linux:3 / samba

Package

Name
samba
Purl
pkg:rpm/azure-linux/samba

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
4.18.3-2

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-88880.json"