Canonical Vulnerabilities and Affected Products
Vulnerabilities associated with Ubuntu 26.04 LTS.
Products
Clear product- LXD30 vulnerabilities
- apport28 vulnerabilities
- Ubuntu Linux13 vulnerabilities
- Juju12 vulnerabilities
- snapd9 vulnerabilities
- Ubuntu 22.04 LTS8 vulnerabilities
- Ubuntu 24.04 LTS8 vulnerabilities
- Ubuntu 20.04 LTS7 vulnerabilities
- Ubuntu 26.04 LTS7 vulnerabilities
- Ubuntu 16.04 LTS6 vulnerabilities
- Ubuntu 18.04 LTS6 vulnerabilities
- ubuntu_linux6 vulnerabilities
- Multipass5 vulnerabilities
- Python-apt4 vulnerabilities
- aptdaemon3 vulnerabilities
- cloud-init3 vulnerabilities
- pulseaudio3 vulnerabilities
- Ubuntu3 vulnerabilities
- ubuntu-pro-client (ubuntu-advantage-tools)3 vulnerabilities
- authd2 vulnerabilities
- Subiquity2 vulnerabilities
- ubantu_kernel2 vulnerabilities
- Ubuntu 14.04 LTS2 vulnerabilities
- Ubuntu Kernel2 vulnerabilities
- unity-firefox-extension2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-8933HIGH | snap-confine Local Privilege Escalation via Capabilities Misconfiguration or Flaw in Execution Environment SetupA local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unpr… CWE-250Jul 21, 2026 | CVSS7.8v3.1 | EPSS0.215% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15226HIGH | snapd snap-confine Sandbox Confinement Bypass via Omission of setuid Restriction in Seccomp TemplatesA sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler (snap-confine). The default seccomp security templates generated by the engine to restrict system calls do not filter or reject process operations capable of creating or manipulating file execution flags with set-user-ID attributes. Consequently, an application running within a strictly confined snap environment can successfully compile or drop binaries and apply setuid proper… CWE-250Jul 21, 2026 | CVSS8.4v3.1 | EPSS0.125% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-5300MEDIUM | AppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via systemd-userdbdAn access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged account-control interface, to interact directly with the io.systemd.Multiplexer and io.systemd.NameServiceSwitch UNIX domain sockets under /run/systemd/userdb/. On systems where th… CWE-212Jul 21, 2026 | CVSS5.6v3.1 | EPSS0.099% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-12391MEDIUM | ubuntu-pro-client Local Privilege Escalation and Information Disclosure via Symlink Arbitrary File Read in collect-logsAn insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file paths or user-accessible log directories when gathering diagnostic information without verifying the file type or ownership. An unprivileged local attacker can exploit this behavior by creating a symbolic link (symlink) at a predictable destination path pointing to an arbitrary… CWE-59Jul 16, 2026 | CVSS5.0v3.1 | EPSS0.159% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-11386CRITICAL | ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injection and Remote Code ExecutionAn input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, … CWE-20Jul 16, 2026 | CVSS9.0v3.1 | EPSS0.342% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9494MEDIUM | ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command LineAn information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL component passed via the command-line arguments (argv), resulting in a URL format such as https://bearer:<token>@esm.ubuntu.com/.../. On systems utilizing a default-mounted /proc fil… CWE-214Jul 16, 2026 | CVSS5.5v3.1 | EPSS0.113% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-12249CRITICAL | Canonical ADSys Trust Store Poisoning via Plaintext HTTP Certificate Auto-EnrollmentAn issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Services (AD CS) certificate auto-enrollment via the vendored Samba client script (internal/policies/certificate/python/vendor_samba/gp/gp_cert_auto_enroll_ext.py), ADSys utilizes a plaintext HTTP connection (http://) instead of a secure HTTPS connection (https://) to request the CA certificate from the Active Directory Certificate Services server (GetCACert). An unauthenticated netw… CWE-348Jun 22, 2026 | CVSS9.0v4.0 | EPSS0.143% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |