Home

Description

Netatalk 2.2.1 through 4.4.2 calls system() after a failed chdir() without properly handling the error condition, which allows a local privileged user to execute unintended commands or cause a minor service disruption under specific conditions.

PUBLISHED Reserved 2026-05-05 | Published 2026-05-21 | Updated 2026-05-22 | Assigner securin




LOW: 2.5CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L

Problem types

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Product status

Default status
unaffected

2.2.1 (semver)
affected

4.5.0 (semver)
unaffected

Credits

Arjun Basnet from Securin finder

References

netatalk.io/security/CVE-2026-44072 (Netatalk Security Advisory CVE-2026-44072) vendor-advisory

cve.org (CVE-2026-44072)

nvd.nist.gov (CVE-2026-44072)

Download JSON