cbcvebase.

Canonical Ubuntu-Pro-Client vulnerabilities

3 known vulnerabilities affecting canonical/ubuntu-pro-client.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2026-11386P2CRITICALCVSS 9.0fixed in 37.32026-07-16
CVE-2026-11386 [CRITICAL] CWE-20 CVE-2026-11386: An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubun An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fi
nvd
CVE-2026-9494P4MEDIUMCVSS 5.5fixed in 37.32026-07-16
CVE-2026-9494 [MEDIUM] CWE-214 CVE-2026-9494: An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advan An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL component passed via the command-li
nvd
CVE-2026-12391P4MEDIUMCVSS 5.0fixed in 37.32026-07-16
CVE-2026-12391 [MEDIUM] CWE-59 CVE-2026-12391: An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-a An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file paths or user-accessible log directories when gathering diagnostic information without verifying the file type or ownership. An un
nvd
Canonical Ubuntu-Pro-Client vulnerabilities | cvebase