Home
LOW: 2.5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:LDefault status
unaffected
2.2.1 (semver)
affected
4.5.0 (semver)
unaffected
Description
Netatalk 2.2.1 through 4.4.2 calls system() after a failed chdir() without properly handling the error condition, which allows a local privileged user to execute unintended commands or cause a minor service disruption under specific conditions.
Problem types
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
2.2.1 (semver)
4.5.0 (semver)
Credits
Arjun Basnet from Securin
References
netatalk.io/security/CVE-2026-44072 (Netatalk Security Advisory CVE-2026-44072)