CVE-2026-2340

Advisory lineage Upstream: 0 Downstream: 4
Analyzed
Published: 27 May 2026, 12:09
Last modified:27 May 2026, 13:22

Vulnerability Summary

Overall Risk (default)
medium
26/100
CVSS Score
6.5 MEDIUM
v3.1 (cve.org)
EPSS Score
0.03% LOW
0% probability
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

27 May 2026, 12:09
Published
Vulnerability first disclosed
27 May 2026, 13:22
Last Modified
Vulnerability information updated

Description

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS Trends

Current EPSS score: 0.03% Percentile: 8%

Techniques & Countermeasures

  • CWE-280Improper Handling of Insufficient Permissions or Privileges

    The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.

Affected Systems

  • redhatenterprise_linux

    7.0 | 8.0 | 9.0 | 10.0

  • redhatopenshift_container_platform

    4.0

  • UnknownSamba

    ≥ 4.1.0

References (3)