CVE-2026-11386
published 2026-07-16CVE-2026-11386: An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files…
PriorityP265critical9CVSS 3.1
AVNACHPRNUINSCCHIHAH
EPSS
0.34%
26.7th percentile
An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\n) characters can successfully inject arbitrary, attacker-controlled deb configuration lines into root-owned APT sources. When combined with the unvalidated additionalPackages[] field—which is passed positionally into a root-executed apt-get install command—an attacker capable of spoofing or manipulating the contract response (e.g., via a compromised internal infrastructure, an intercepted connection utilizing a trusted CA, or local logical bugs) can force the client to fetch and install malicious packages. This ultimately leads to arbitrary code execution with root privileges on the affected system. This component is preinstalled on supported Ubuntu Server releases and auto-attaches by default on cloud provider Ubuntu Pro images.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu-pro-client | < 37.3 | 37.3 |
| ubuntu | ubuntu-advantage-tools | — | — |
CVSS provenance
nvdv3.19.0CRITICALCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
vendor_ubuntu9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Canonical ubuntu-pro-client APT Source File Generation ubuntu-.list str.format directives.aptURL/suites[]/additionalPackages[] input validation (EUVD-2026-44911 / Nessus ID 327436)
vuldb·2026-07-18·CVSS 9.0
CVE-2026-11386 [CRITICAL] Canonical ubuntu-pro-client APT Source File Generation ubuntu-.list str.format directives.aptURL/suites[]/additionalPackages[] input validation (EUVD-2026-44911 / Nessus ID 327436)
A vulnerability, which was classified as very critical, has been found in Canonical ubuntu-pro-client. This affects the function str.format of the file /etc/apt/sources.list.d/ubuntu-.list of the component APT Source File Generation. This manipulation of the argument directives.aptURL/suites[]/additionalPackages[] causes improper input validation.
This vulnerability appears as CVE-2026-11386. The attack may be initiated remotely. There is no available exploit.
GHSA
An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools).
ghsa_unreviewed·2026-07-16
CVE-2026-11386 [CRITICAL] CWE-20 An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools).
An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\n) characters can successfully inject arbitrary, attacker-controlled deb configuration lines into root-owned APT sources. When combined with the unvalidated additionalPackages[] field—which is passed positionally into a root-exe
Ubuntu
Ubuntu Advantage Tools (pro client) vulnerabilities
vendor_ubuntu·2026-07-16·CVSS 9.0
CVE-2026-9494 [CRITICAL] Ubuntu Advantage Tools (pro client) vulnerabilities
Title: Ubuntu Advantage Tools (pro client) vulnerabilities
Summary: Several security issues were fixed in Ubuntu Advantage Tools.
Bilal Teke discovered that Ubuntu Advantage Tools exposed the Pro bearer
token in command-line arguments when validating APT credentials. A local
attacker could possibly use this issue to obtain sensitive information
and gain unauthorized access to Ubuntu Pro repositories. (CVE-2026-9494)
Frederick Jerusha discovered that Ubuntu Advantage Tools did not properly
validate data received from the contract server when writing APT source
files. An attacker could possibly use this issue to inject arbitrary APT
configuration and execute arbitrary code. (CVE-2026-11386)
Mateusz Gierblinski discovered that Ubuntu Advantage Tools did not
properly handle symbolic links
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-16
Published