A vulnerability, which was classified as problematic, has been found in cURL up to 8.19.0. The impacted element is an unknown function of the component SMB Connection Handler. This manipulation causes Remote Code Execution.

This vulnerability is registered as CVE-2026-5773. Remote exploitation of the attack is possible. No exploit is available.

It is advisable to upgrade the affected component.