A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-44066

CVE-2026-44066: Netatalk Information Disclosure Flaw

CVE-2026-44066 is an information disclosure vulnerability in Netatalk versions 3.1.0 through 4.4.2 caused by heap out-of-bounds reads. This article covers the technical details, affected versions, and mitigation strategies.

Published: May 21, 2026

CVE-2026-44066 Overview

CVE-2026-44066 affects Netatalk, an open-source implementation of the Apple Filing Protocol (AFP) used to share files with macOS clients. The vulnerability is a set of heap out-of-bounds reads [CWE-125] in the Spotlight Remote Procedure Call (RPC) unmarshalling code. It impacts Netatalk versions 3.1.0 through 4.4.2.

A remote authenticated attacker can send crafted Spotlight RPC requests to read adjacent heap memory or trigger a limited service disruption. The flaw exposes sensitive in-process data and can degrade availability of the AFP daemon.

Critical Impact

Authenticated remote attackers can leak heap memory contents from the Netatalk daemon and induce minor service disruption through malformed Spotlight RPC traffic.

Affected Products

  • Netatalk 3.1.0 through 3.1.x
  • Netatalk 3.2.x and 4.x branches
  • Netatalk versions up to and including 4.4.2

Discovery Timeline

  • 2026-05-21 - CVE-2026-44066 published to NVD
  • 2026-05-21 - Last updated in NVD database

Technical Details for CVE-2026-44066

Vulnerability Analysis

Netatalk exposes Apple's Spotlight search protocol over AFP through an RPC mechanism. The server unmarshals binary structures sent by clients into in-memory objects representing queries, attribute requests, and metadata containers. Multiple code paths in this unmarshalling logic fail to validate length and offset fields against the bounds of the source buffer.

When the daemon parses a malformed Spotlight message, it reads bytes past the end of the allocated heap region. The attacker receives the leaked data either through reflected response fields or through observable error behavior. The bug class is a classic out-of-bounds read [CWE-125] rather than a write primitive.

The access scope is limited to authenticated AFP sessions. The integrity impact is rated none, while confidentiality impact is high and availability impact is low.

Root Cause

The Spotlight RPC parser trusts attacker-controlled length, count, and offset values embedded in serialized request structures. The unmarshalling routines advance read pointers based on these untrusted values without verifying that the resulting positions remain inside the input buffer. Multiple distinct code paths share this pattern, producing several variants of the same flaw.

Attack Vector

An attacker first authenticates to the AFP service with valid credentials. The attacker then opens a Spotlight session against a shared volume and submits crafted RPC messages with manipulated length and offset fields. The Netatalk daemon parses these messages and returns response data containing adjacent heap memory, or terminates the session under specific malformed inputs.

The vulnerability is described in prose only because no public proof-of-concept code is associated with this CVE. Refer to the Netatalk Security Advisory for CVE-2026-44066 for protocol-level technical details.

Detection Methods for CVE-2026-44066

Indicators of Compromise

  • Unexpected afpd child process crashes or abnormal termination entries in system logs correlated with active AFP client sessions.
  • AFP sessions originating from authenticated users that issue unusually large or malformed Spotlight query payloads.
  • Repeated Spotlight RPC requests from a single client followed by session resets or daemon error messages.

Detection Strategies

  • Monitor afpd process behavior for repeated faults, segmentation signals, or memory access errors during Spotlight operations.
  • Inspect AFP traffic for Spotlight RPC messages with length or count fields that exceed the size of the enclosing message.
  • Correlate authentication events with subsequent Spotlight query volume per user to surface accounts probing the parser.

Monitoring Recommendations

  • Forward afpd logs and host audit data to a centralized analytics platform and alert on daemon restarts.
  • Track per-user AFP session counts, Spotlight query rates, and response sizes to baseline normal behavior.
  • Enable verbose Netatalk logging in environments where Spotlight is exposed and review parser-related warnings.

How to Mitigate CVE-2026-44066

Immediate Actions Required

  • Upgrade Netatalk to a fixed release published after version 4.4.2 as described in the vendor advisory.
  • Audit AFP user accounts and remove or rotate credentials for users who do not require file share access.
  • Restrict network reachability of the AFP service to trusted client subnets using host or network firewalls.

Patch Information

The Netatalk project published a security advisory at Netatalk Security Advisory for CVE-2026-44066. Apply the patched release referenced in that advisory to all hosts running Netatalk 3.1.0 through 4.4.2. Rebuild and redeploy any container images or appliance firmware that bundle vulnerable Netatalk binaries.

Workarounds

  • Disable Spotlight support in afp.conf by setting spotlight = no on shares and globally where search is not required.
  • Block TCP port 548 at the network perimeter and limit AFP access to VPN or management networks.
  • Where feasible, migrate clients to SMB and stop the Netatalk service until the patched version is deployed.
bash
# Configuration example: disable Spotlight in Netatalk afp.conf
[Global]
  spotlight = no

[Share]
  path = /srv/share
  spotlight = no

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeInformation Disclosure

  • Vendor/TechNetatalk

  • SeverityHIGH

  • CVSS Score7.1

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityLow
  • CWE References
  • CWE-125
  • Technical References
  • Netatalk Security Advisory for CVE-2026-44066
  • Related CVEs
  • CVE-2026-7836: Netatalk Information Disclosure Flaw

  • CVE-2026-44069: Netatalk Information Disclosure Flaw

  • CVE-2026-44067: Netatalk Information Disclosure Flaw

  • CVE-2026-44064: Netatalk Information Disclosure Flaw
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English