CVE-2026-44073
In Netatalk 1.5.0 through 4.4.2, seteuid failure ignored in auth modules. Fixed in 4.5.0.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
- EPSS probability
- 0.28%
- CWE
- CWE-273
- Published
- 2026-05-21
- Last modified
- 2026-05-21
Affected products
- Netatalk Netatalk
- Netatalk Netatalk
Weakness type
Related vulnerabilities
- CVE-2026-58089 — hwpmc fails to detach PMCs during exec credential transitions
- CVE-2026-61897 — accountsservice: incomplete privilege drop when running Ubuntu-specific language helper scripts
- CVE-2026-58086 — ktrace(2) privilege incorrectly validated in jails
- CVE-2026-49421 — unlinkat(2) ignores AT_RESOLVE_BENEATH flag
- CVE-2026-54552 — sh _uid does not drop supplementary groups (incomplete privilege drop)
- CVE-2026-60085 — PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandbox
- CVE-2026-32107 — xrdp: Fail-open privilege drop in sesexec — child processes may execute as root if setuid fails
- CVE-2026-21882 — theshit's Improper Privilege Dropping Allows Local Privilege Escalation via Command Re-execution