CVE-2026-44073 Details
Description
Authentication modules in Netatalk 1.5.0 through 4.4.2 fail to check the return value of seteuid(), which may allow a remote authenticated attacker to retain elevated privileges under error conditions.
A vulnerability exists in Netatalk versions 1.5.0 through 4.4.2, where authentication modules fail to properly handle errors related to privilege changes. Specifically, these modules log failures but continue executing, which could pose a risk if a process unexpectedly fails to drop privileges as intended. While attackers cannot typically exploit this issue under normal conditions, it creates a potential defense-in-depth concern.
Users can upgrade to Netatalk version 4.5.0 or later, which addresses this vulnerability. Alternatively, the patch for this vulnerability can be applied to the Netatalk 4.4.2 source code. The Netatalk team advises against applying the patch to existing deployments due to the low risk of practical exploitation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 21, 2026CISA-ADP
Assessed May 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://netatalk.io/security/CVE-2026-44073 | securin | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-273 | Improper Check for Dropped Privileges | securin |
Affected Products
| Product | Versions |
|---|---|
| Netatalk | >= 1.5.0, <= 4.4.2 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | securin |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 21, 2026 | CVE Modified | securin |
| May 21, 2026 | New CVE Received | securin |
Volerion