Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 12 Jun 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache apache-airflow-providers-samba
|
|
| CPEs | cpe:2.3:a:apache:apache-airflow-providers-samba:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache apache-airflow-providers-samba
|
Wed, 10 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 09 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 09 Jun 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache airflow Samba Provider |
|
| Vendors & Products |
Apache
Apache airflow Samba Provider |
Tue, 09 Jun 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an object named with `../` segments resolved a write path outside the configured `destination_path`. An attacker able to write objects into the source GCS bucket — typically an external data producer distinct from the trusted DAG author — could write files to arbitrary locations on the Samba target when the operator ran. Upgrade apache-airflow-providers-samba to 4.12.6 or later, which validates the resolved destination stays within `destination_path`. | |
| Title | Apache Airflow Samba provider: Path traversal in GCSToSambaOperator via GCS object names | |
| Weaknesses | CWE-22 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-06-10T17:37:57.296Z
Reserved: 2026-06-01T17:37:44.180Z
Link: CVE-2026-49818
Updated: 2026-06-09T11:03:31.617Z
Status : Analyzed
Published: 2026-06-09T09:16:30.443
Modified: 2026-06-12T15:51:19.927
Link: CVE-2026-49818
No data.
OpenCVE Enrichment
Updated: 2026-06-09T21:45:05Z