CVE-2026-2340 in Canonical and Red Hat Products
Published on May 27, 2026
Samba: vfs_worm does not block directory modification
Vulnerability Analysis
CVE-2026-2340 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.
Timeline
Reported to Red Hat.
Made public. 75 days later.
Weakness Type
Improper Handling of Insufficient Permissions or Privileges
The application does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the application in an invalid state.
Products Associated with CVE-2026-2340
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-2340 are published in these products: