PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Network Vulnerabilities·Updated Jun 22, 2026

Samba Printing Subsystem - Remote Code Execution

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3.1k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-4480
9.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Red Hat Enterprise Linux 10by Red Hat
AFFECTED< *SAFE ✓≥ *
Red Hat Enterprise Linux 10.0 Extended Update Supportby Red Hat
AFFECTED< *SAFE ✓≥ *
Red Hat Enterprise Linux 7 Extended Lifecycle Supportby Red Hat
AFFECTED< *SAFE ✓≥ *
Red Hat Enterprise Linux 7 Extended Lifecycle Supportby Red Hat
AFFECTED< *SAFE ✓≥ *
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.