All versions of Samba starting with 4.21.0 are vulnerable to a improper authorization issue. smbd does not pick up group membership changes when re-authenticating an expired SMB session.