ZeroHour

CVE-2026-25706

large

Root command injection in SUSE yast2-samba-client during Active Directory joins

CVSS 4.0
7.5 high
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-25706 is an OS command injection flaw (CWE-78) in yast2-samba-client, the YaST module used to join SUSE and openSUSE machines to Active Directory domains, in all versions through 5.0.4. It is triggered when an adversary who controls the content of the AD directory tree — either a rogue domain controller or a directory user delegated the right to create objects — supplies hostile directory data that the join process fails to properly neutralize. A successful attack yields execution of arbitrary commands with root privileges on the SUSE/openSUSE machine being joined to the domain. Exposure requires an administrator to actually run the domain join (per the CVSS 4.0 vector, user interaction is active and attack complexity is rated present), so an arbitrary internet attacker cannot trigger it remotely against a random target; the realistic victims are hosts joined to a domain whose controllers or delegated users have been compromised. No exploitation is confirmed: the flaw is absent from CISA KEV, has no known public proof-of-concept, and EPSS estimates a 0.4% probability of exploitation in the next 30 days.

What to do: Update yast2-samba-client as soon as SUSE/openSUSE publishes a release beyond 5.0.4 in their advisory channels. Until patched, only join hosts to AD forests you fully control and trust, verify that all domain controllers are legitimate, and restrict delegated directory users' ability to create objects. Audit recently joined hosts and treat any domain join performed against a compromised AD tree as potential root compromise of the joined machine.

Affected
SUSE / openSUSE yast2-samba-client (YaST2 Samba client/domain-join module)all versions through 5.0.4 (fixed in a release above 5.0.4; fixed version not specified in the data)
Estimated exposure
large≈100,000+ SUSE/openSUSE systems ship the vulnerable module, with the plausibly exploitable subset — hosts joined to AD via YaST — likely in the tens of… — yast2-samba-client is part of the standard YaST toolset in SUSE Linux Enterprise and openSUSE (a multi-million-install base), so the estimate assumes enterprise Active Directory-join usage at roughly 1–10% of SUSE servers; no public scan…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who controls the content of an Active Directory directory tree - a rogue domain controller, or a directory user delegated the right to create objects - to execute arbitrary commands as root on a machine being joined to that domain. This issue affects yast2-samba-client through 5.0.4.

Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.