CVE-2026-3012: Red Hat Enterprise Linux
Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.
Affected products
- Red Hat Enterprise Linux: version 7.0 only; version 9.0 only
- Red Hat Openshift Container Platform: version 4.0 only
- Samba Samba: from 4.16.0, before 4.21.0 (fixed in 4.21.0)
Published 2026-05-27. Last modified 2026-10-08.