Samba Patches Critical Domain Takeover Flaws Across All Branches

Published by

The Samba Team released critical security updates on July 28, 2026, for versions 4.24.5, 4.23.10, and 4.22.11, addressing six vulnerabilities that affect Samba Active Directory domain controllers. Two of these vulnerabilities, rated CVSS 8.8, allow low-privilege authenticated users to bypass LDAP access controls and potentially take over an Active Directory domain, necessitating immediate patching by administrators. The updates also fix additional medium-severity issues related to DNS TSIG signing, KDC stability, and CTDB protocol integrity. Overall, the rapid response by the Samba Team ensures that all active branches are secured against the identified flaws



Samba Patches Critical Domain Takeover Flaws Across All Branches

The Samba Team issued coordinated security updates for versions 4.24.5, 4.23.10, and 4.22.11 on July 28, 2026, addressing six vulnerabilities across all active maintenance branches. Two of these flaws, both rated CVSS 8.8 and discovered by OpenAI Security Research, allow low-privilege authenticated users to bypass LDAP access controls and fully compromise an Active Directory domain. Because no workarounds exist for the critical issues, administrators are strongly urged to apply the patches immediately to prevent domain takeover and cryptographic key extraction. The release also resolves additional medium-severity issues affecting DNS TSIG signing, KDC stability, and CTDB clustering protocol integrity.

Samba Patches Critical Domain Takeover Flaws Across All Branches @ Linux Compatible