CVE-2026-3012
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.
Scoring
- Severity
- HIGH
- CVSS base score
- 8
- CVSS vector
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
- EPSS probability
- 0.26%
- CWE
- CWE-345
- Published
- 2026-05-27
- Last modified
- 2026-09-15
Affected products
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support
- Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
- Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
- Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support
- Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service
Weakness type
Related vulnerabilities
- CVE-2026-44523 — Note Mark: JWT Secret Weakness allows Full Account Takeover via token forgery
- CVE-2026-33243 — barebox: FIT Signature Verification Bypass Vulnerability
- CVE-2026-48781 — Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery
- CVE-2026-80172 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-28185 — WordPress Log in with Google plugin <= 1.4.2 - Broken Authentication vulnerability
- CVE-2026-53513 — Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registration
- CVE-2026-33471 — nimiq-block has skip block quorum bypass via out-of-range BitSet indices & u16 truncation
- CVE-2026-45058 — electerm: Import unsafe bookmark data could lead to unsafe operation when click local type bookmark