Record summary

CVE-2026-9494 has a selected CVSS score of 5.5 (medium).

Description

An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL component passed via the command-line arguments (argv), resulting in a URL format such as https://bearer:<token>@esm.ubuntu.com/.../. On systems utilizing a default-mounted /proc file system where process-hiding mitigations (such as hidepid) are disabled, an unprivileged local attacker can monitor system processes and read the sensitive bearer token directly from /proc/cmdline while the helper process is actively running. This leaked token can subsequently be used to gain unauthorized access to the victim's Ubuntu Pro or Expanded Security Maintenance (ESM) repositories.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 16, 2026 · Source: CVE List

Affected products and versions

8
ProductSourceVersion rangeStatus

Ubuntu 14.04 LTS

Browse Canonical / Ubuntu 14.04 LTSubuntu-advantage-tools

Default status: affected

CVE List19.7ubuntu0.1unaffected

Ubuntu 16.04 LTS

Browse Canonical / Ubuntu 16.04 LTSubuntu-advantage-tools

Default status: affected

CVE List37.1ubuntu0~16.04.1unaffected

Ubuntu 18.04 LTS

Browse Canonical / Ubuntu 18.04 LTSubuntu-advantage-tools

Default status: affected

CVE List37.1ubuntu0~18.04.1unaffected

Ubuntu 20.04 LTS

Browse Canonical / Ubuntu 20.04 LTSubuntu-advantage-tools

Default status: affected

CVE List37.1ubuntu0~20.04.1unaffected

Ubuntu 22.04 LTS

Browse Canonical / Ubuntu 22.04 LTSubuntu-advantage-tools

Default status: affected

CVE List37.2ubuntu~22.04.1unaffected

Ubuntu 24.04 LTS

Browse Canonical / Ubuntu 24.04 LTSubuntu-advantage-tools

Default status: affected

CVE List37.2ubuntu~24.04.1unaffected

Ubuntu 26.04 LTS

Browse Canonical / Ubuntu 26.04 LTSubuntu-advantage-tools

Default status: affected

CVE List37.2ubuntu0.1unaffected

ubuntu-pro-client (ubuntu-advantage-tools)

Browse Canonical / ubuntu-pro-client (ubuntu-advantage-tools)ubuntu-pro-client

Default status: unaffected

CVE ListBefore 37.3affected

References

2