PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-45699 Netatalk CVE debrief

A stack-based buffer overflow vulnerability exists in Netatalk's afpd daemon due to an integer underflow in the copydir() function, which can lead to potential code execution. The issue affects versions 3.1.19 through 4.4.2 and is patched in version 4.4.3. This vulnerability can be exploited by attackers to execute arbitrary code on affected systems, potentially leading to unauthorized access and data breaches. Defenders should assess exposure, verify versions, and apply patches or workarounds as necessary to prevent exploitation.

Vendor
Netatalk
Product
Unknown
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-14
Original CVE updated
2026-09-18
Advisory published
2026-08-14
Advisory updated
2026-09-18

Who should care

Defenders of Unix-like operating systems using Netatalk file server suite should assess exposure and apply patches or workarounds as necessary. This includes verifying the version of Netatalk in use, applying the patch or workaround, and configuring AFP shared volumes as single file systems to prevent exploitation. Security teams should also review compensating controls for exposed systems and track exceptions and retest remediated assets.

Why it matters

CVE-2026-45699 is a high-severity vulnerability in Netatalk that can lead to potential code execution. Defenders of Unix-like operating systems using Netatalk should assess exposure, verify versions, and apply patches or workarounds as necessary.

  • Potential code execution on affected Netatalk installations
  • Verification of Netatalk version and configuration required
  • Patching or workarounds necessary to prevent exploitation
  • Configuration changes to AFP shared volumes may be required

Technical summary

The copydir() function in Netatalk's afpd daemon has a stack-based buffer overflow due to an integer underflow, allowing for potential code execution. This issue affects Netatalk versions 3.1.19 through 4.4.2. The vulnerability can be exploited by attackers to execute arbitrary code on affected systems, potentially leading to unauthorized access and data breaches. Defenders should assess exposure, verify versions, and apply patches or workarounds as necessary to prevent exploitation. The vulnerability was patched in version 4.4.3 of Netatalk.

Defensive priority

High

Recommended defensive actions

  • Assess exposure of Netatalk installations to this vulnerability
  • Verify if Netatalk versions 3.1.19 through 4.4.2 are in use
  • Apply patch version 4.4.3 or later
  • Configure AFP shared volumes as single file systems
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. The vulnerability was patched in version 4.4.3 of Netatalk. Defenders should verify the version of Netatalk in use and apply the patch or workaround as necessary. The CVE record and NVD entry also provide additional information on the vulnerability, including its CVSS score and affected versions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-45699 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-45699

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-45699 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45699

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.