Home
HIGH: 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
3.1.4 (semver)
affected
4.4.3 (semver)
unaffected
Description
A logic error involving bitwise OR operations in Netatalk 3.1.4 through 4.4.2 allows a remote authenticated attacker to inject OS commands and execute arbitrary code.
Problem types
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
3.1.4 (semver)
4.4.3 (semver)
Credits
Arjun Basnet from Securin
References
netatalk.io/security/CVE-2026-44055 (Netatalk Security Advisory CVE-2026-44055)