CVE-2026-3012

A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

History

10 Jun 2026, 16:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:25049 -

08 Jun 2026, 14:59

Type Values Removed Values Added
References () https://access.redhat.com/errata/RHSA-2026:22644 - () https://access.redhat.com/errata/RHSA-2026:22644 - Issue Tracking
References () https://access.redhat.com/errata/RHSA-2026:22963 - () https://access.redhat.com/errata/RHSA-2026:22963 - Issue Tracking
References () https://access.redhat.com/security/cve/CVE-2026-3012 - () https://access.redhat.com/security/cve/CVE-2026-3012 - Mitigation, Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2447319 - () https://bugzilla.redhat.com/show_bug.cgi?id=2447319 - Issue Tracking, Third Party Advisory
References () https://bugzilla.samba.org/show_bug.cgi?id=16003 - () https://bugzilla.samba.org/show_bug.cgi?id=16003 - Issue Tracking, Mitigation, Vendor Advisory
First Time Redhat enterprise Linux
Redhat
Samba
Samba samba
Redhat openshift Container Platform
CPE cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

04 Jun 2026, 00:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:22963 -

03 Jun 2026, 06:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:22644 -

27 May 2026, 12:17

Type Values Removed Values Added
CWE CWE-345

27 May 2026, 11:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-27 11:16

Updated : 2026-06-10 16:17


NVD link : CVE-2026-3012

Mitre link : CVE-2026-3012

CVE.ORG link : CVE-2026-3012


JSON object : View

Products Affected

samba

  • samba

redhat

  • openshift_container_platform
  • enterprise_linux
CWE
CWE-345

Insufficient Verification of Data Authenticity