CVE-2026-44072: Netatalk

Low severity, CVSS 3.0. EPSS: 0.1% chance of exploitation in the next 30 days.

Netatalk 2.2.1 through 4.4.2 calls system() after a failed chdir() without properly handling the error condition, which allows a local privileged user to execute unintended commands or cause a minor service disruption under specific conditions.

Affected products

  • Netatalk Netatalk: from 2.2.1, up to and including 4.4.2

Published 2026-05-21. Last modified 2026-07-23.