THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-3012 (HIGH 8.0) — A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker w

[NVD] CVE-2026-3012 (HIGH 8.0) — A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker w

lownvdPublished 2026-05-27

CVE-2026-3012 CVSS: 8.0 HIGH Published: 2026-05-27T11:16:18.357

A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffi

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-3012