CVE-2026-44076

Insufficient sanitization of volume paths in Netatalk 3.1.0 through 4.4.2 allows a local privileged user to inject OS commands and execute arbitrary code via a crafted volume path.
Configurations

No configuration.

History

21 May 2026, 09:16

Type Values Removed Values Added
Summary (en) In Netatalk 3.1.0 through 4.4.2, shell injection via volume path. Fixed in 4.4.3. (en) Insufficient sanitization of volume paths in Netatalk 3.1.0 through 4.4.2 allows a local privileged user to inject OS commands and execute arbitrary code via a crafted volume path.

21 May 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-21 08:16

Updated : 2026-05-21 15:20


NVD link : CVE-2026-44076

Mitre link : CVE-2026-44076

CVE.ORG link : CVE-2026-44076


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')