PatchSiren cyber security CVE debrief
CVE-2026-1933 Red Hat CVE debrief
A flaw in Samba's handling of NTFS-style reparse points on read-only shares allows authenticated users with underlying filesystem write permissions to modify reparse point metadata. This could potentially alter SMB-visible file behavior, including converting files into symbolic links or other reparse point types. System administrators and security teams should assess exposure, verify user permissions, and prioritize patching to prevent exploitation. The vulnerability exists due to missing SMB-layer access checks, allowing modifications even on read-only exports.
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-27
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-05-27
- Advisory updated
- 2026-10-08
Who should care
System administrators and security teams responsible for Samba shares, especially those with read-only access, should assess exposure and verify user permissions to prevent potential modifications to reparse point metadata.
Why it matters
CVE-2026-1933 allows authenticated users to modify reparse point metadata on read-only Samba shares, potentially altering file behavior. System administrators and security teams should assess exposure, verify user permissions, and prioritize patching to prevent exploitation.
- Modification of SMB-visible file behavior through reparse point metadata changes.
- Potential conversion of files into symbolic links or other reparse point types.
- Need for verification of user permissions and reparse point configurations.
- Priority for applying patches or updates from Red Hat.
Technical summary
Authenticated users with underlying filesystem write permissions can create or delete reparse point metadata through SMB operations on shares configured with read only = yes. This could potentially convert files into symbolic links or other reparse point types. The vulnerability exists due to missing SMB-layer access checks, allowing modifications even on read-only exports. Affected systems should be reviewed for exposure, and user permissions should be verified to prevent exploitation. Patches or updates from Red Hat should be applied as available.
Defensive priority
Assess exposure of Samba shares with read-only access, verify user permissions, and review reparse point configurations.
Recommended defensive actions
- Review Samba share configurations for read-only access and verify user permissions.
- Assess the exposure of Samba shares with read-only access.
- Monitor for unusual reparse point modifications.
- Apply patches or updates from Red Hat as available.
- Verify reparse point configurations and user permissions.
- Perform a thorough review of affected systems and apply mitigations.
- Track and document changes to reparse point metadata.
Evidence notes
The CVE record and NVD detail provide information on the flaw in Samba's handling of NTFS-style reparse points. Red Hat errata advisories offer additional context on affected systems and potential mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-1933 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-1933
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-1933 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-1933
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:22644
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:22963
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:25049
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:25979
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:28053
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:28054
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:28055
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:28056
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.