Samba certificate auto-enrollment GPO CA certificate installation over HTTP without verification
CVE-2026-3012 is a flaw in Samba's certificate auto-enrollment Group Policy handling affecting Samba versions since 4.16. When certificate auto-enrollment is enabled on a domain member, Samba may fetch a CA certificate over plain HTTP and install it into the local trust store without proper verification. The vulnerable behavior occurs in the auto-enrollment GPO path used by domain members, where Samba follows a certificate retrieval URL pattern associated with Microsoft NDES even though a more secure encrypted LDAP channel is available for domain members. Because the CA certificate is obtained over an unencrypted and insufficiently validated channel, an attacker who can intercept or redirect the HTTP traffic can substitute an attacker-controlled CA certificate, which is then trusted by the affected host.
Are you exposed to this one?
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
Impact, mitigation & remediation
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
Impact
What an attacker gets, and what they’ve been doing with it.
Mitigation
If you can’t patch tonight, do this now.
Remediation
Patch, then assume compromise.
Exploits
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Affected products & vendors
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
Recent activity
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability in Samba's certificate auto-enrollment Group Policy handling that can allow an attacker able to intercept or redirect network traffic to provide a malicious CA certificate, leading to interception or spoofing of trusted communications.
A Samba vulnerability in certificate auto-enrollment where a CA certificate can be fetched over plain HTTP without verification instead of using protected LDAP, allowing interception and installation of an attacker-chosen certificate in the trust store.
The version that knows your environment.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.