Home
MEDIUM: 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
3.1.0 (semver)
affected
4.4.3 (semver)
unaffected
Description
Insufficient sanitization of volume paths in Netatalk 3.1.0 through 4.4.2 allows a local privileged user to inject OS commands and execute arbitrary code via a crafted volume path.
Problem types
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
3.1.0 (semver)
4.4.3 (semver)
Credits
Arjun Basnet from Securin
References
netatalk.io/security/CVE-2026-44076 (Netatalk Security Advisory CVE-2026-44076)