A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.
[POC] CVE-2026-4480 — HTB-Abducted-Writeup
HTB "Abducted" write-up. Exploit CVE-2026-4480 (Samba RCE) → SMB wide links → systemd → root. Full methodology and flags.
[POC] CVE-2026-4480 — CVE-2026-4480-exploit-poc
This is an exploit poc for CVE-2026-4480
[POC] CVE-2026-4480 — CVE-2026-4480
smb spooler to RCE
[POC] CVE-2026-4480 — CVE-2026-4480
CVE-2026-4480
[POC] CVE-2026-4480 — CVE-2026-4480
Exploit CVE-2026-4480
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free