CVE-2010-0926

Exp

The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, and access arbitrary files, by using the symlink command in smbclient to create a symlink containing .. (dot dot) sequences, related to the combination of the unix extensions and wide links options.

Published: 2010-03-10 Last update: 2026-04-29 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2010-0926 is rated High Exploit Risk (67.3/100): CVSS Low severity, with high exploitation likelihood (EPSS 56.31%, 98th percentile). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +3.90% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2010-0926

EDB-ID Source Kind Published Link
33598 exploit_db edb 2010-02-04 Exploit-DB ↗
33599 exploit_db edb 2010-02-04 Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2010-0926

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-05-22 52.41% 56.31% +3.90%
2 2026-04-12 29.36% 52.41% +23.05%
3 2025-12-01 29.36%

Full EPSS history (24 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2010-0926

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
3.5 2.0 LOW
AV:N/AC:M/Au:S/C:P/I:N/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:S)
A single authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
6.8 2.9 [email protected]

Weakness enumeration for CVE-2010-0926

OS Trackers for CVE-2010-0926

vendor priority summary link
debian low CVE-2010-0926 low priority: Debian including 1 source packages (samba), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2010-0926
redhat low https://access.redhat.com/security/cve/CVE-2010-0926
suse low CVE-2010-0926 severity low: SUSE including 660 source package names (cifs-mount-3.2.7-11.9.1, cifs-mount-3.4.3-1.17.2, …), 1029 product×package rows across 33 product lines (SUSE Linux Enterprise Desktop 12, SUSE Linux Enterprise Desktop 12 SP1, … (33 product lines)): Fixed 1029. https://www.suse.com/security/cve/CVE-2010-0926/
ubuntu medium CVE-2010-0926 medium priority: Ubuntu including 1 source packages (samba), 6 status rows across 6 suites (dapper, hardy, intrepid, jaunty, karmic, upstream): released 6. https://ubuntu.com/security/CVE-2010-0926

Affected software / configurations for CVE-2010-0926

Vendor Product Version Raw CPE
samba samba 3.3.0 cpe:2.3:a:samba:samba:3.3.0:*:*:*:*:*:*:*
samba samba 3.3.1 cpe:2.3:a:samba:samba:3.3.1:*:*:*:*:*:*:*
samba samba 3.3.2 cpe:2.3:a:samba:samba:3.3.2:*:*:*:*:*:*:*
samba samba 3.3.3 cpe:2.3:a:samba:samba:3.3.3:*:*:*:*:*:*:*
samba samba 3.3.4 cpe:2.3:a:samba:samba:3.3.4:*:*:*:*:*:*:*
samba samba 3.3.5 cpe:2.3:a:samba:samba:3.3.5:*:*:*:*:*:*:*
samba samba 3.3.6 cpe:2.3:a:samba:samba:3.3.6:*:*:*:*:*:*:*
samba samba 3.3.7 cpe:2.3:a:samba:samba:3.3.7:*:*:*:*:*:*:*
samba samba 3.3.8 cpe:2.3:a:samba:samba:3.3.8:*:*:*:*:*:*:*
samba samba 3.3.9 cpe:2.3:a:samba:samba:3.3.9:*:*:*:*:*:*:*
samba samba 3.3.10 cpe:2.3:a:samba:samba:3.3.10:*:*:*:*:*:*:*
samba samba 3.4.0 cpe:2.3:a:samba:samba:3.4.0:*:*:*:*:*:*:*
samba samba 3.4.1 cpe:2.3:a:samba:samba:3.4.1:*:*:*:*:*:*:*
samba samba 3.4.2 cpe:2.3:a:samba:samba:3.4.2:*:*:*:*:*:*:*
samba samba 3.4.3 cpe:2.3:a:samba:samba:3.4.3:*:*:*:*:*:*:*
samba samba 3.4.4 cpe:2.3:a:samba:samba:3.4.4:*:*:*:*:*:*:*
samba samba 3.4.5 cpe:2.3:a:samba:samba:3.4.5:*:*:*:*:*:*:*
samba samba 3.5.0 cpe:2.3:a:samba:samba:3.5.0:*:*:*:*:*:*:*

References for CVE-2010-0926

URL Tags
http://archives.neohapsis.com/archives/fulldisclosure/2010-02/0083.html
http://archives.neohapsis.com/archives/fulldisclosure/2010-02/0107.html
http://archives.neohapsis.com/archives/fulldisclosure/2010-02/0108.html
http://blog.metasploit.com/2010/02/exploiting-samba-symlink-traversal.html
http://gitweb.samba.org/?p=samba.git%3Ba=commit%3Bh=bd269443e311d96ef495a9db47d1b95eb83bb8f4
http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html
http://marc.info/?l=full-disclosure&m=126538598820903&w=2
http://marc.info/?l=oss-security&m=126539592603079&w=2
http://marc.info/?l=oss-security&m=126540402215620&w=2
http://marc.info/?l=oss-security&m=126540733320471&w=2
http://marc.info/?l=oss-security&m=126545363428745&w=2
http://marc.info/?l=oss-security&m=126777580624790&w=2
http://marc.info/?l=samba-technical&m=126539387432412&w=2
http://marc.info/?l=samba-technical&m=126540011609753&w=2
http://marc.info/?l=samba-technical&m=126540100511357&w=2
http://marc.info/?l=samba-technical&m=126540248613395&w=2
http://marc.info/?l=samba-technical&m=126540277713815&w=2
http://marc.info/?l=samba-technical&m=126540290614053&w=2
http://marc.info/?l=samba-technical&m=126540376915283&w=2
http://marc.info/?l=samba-technical&m=126540475116511&w=2
http://marc.info/?l=samba-technical&m=126540477016522&w=2
http://marc.info/?l=samba-technical&m=126540539117328&w=2
http://marc.info/?l=samba-technical&m=126540608318301&w=2
http://marc.info/?l=samba-technical&m=126540695819735&w=2
http://marc.info/?l=samba-technical&m=126547903723628&w=2
http://marc.info/?l=samba-technical&m=126548356728379&w=2
http://marc.info/?l=samba-technical&m=126549111204428&w=2
http://marc.info/?l=samba-technical&m=126555346721629&w=2
http://secunia.com/advisories/39317
http://www.openwall.com/lists/oss-security/2010/02/06/3
http://www.openwall.com/lists/oss-security/2010/03/05/3
http://www.samba.org/samba/news/symlink_attack.html Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=562568
https://bugzilla.samba.org/show_bug.cgi?id=7104
cvelogic Threat Intelligence