Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5005 articles · 188942 vulns · 37/41 feeds (7d)
← Back to list
9.0
CVE-2026-11386PATCHED
canonical · ubuntu-pro-client

ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injection and Remote Code Execution

Description

An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\n) characters can successfully inject arbitrary, attacker-controlled deb configuration lines into root-owned APT sources. When combined with the unvalidated additionalPackages[] field—which is passed positionally into a root-executed apt-get install command—an attacker capable of spoofing or manipulating the contract response (e.g., via a compromised internal infrastructure, an intercepted connection utilizing a trusted CA, or local logical bugs) can force the client to fetch and install malicious packages. This ultimately leads to arbitrary code execution with root privileges on the affected system. This component is preinstalled on supported Ubuntu Server releases and auto-attaches by default on cloud provider Ubuntu Pro images.

Affected Products

VendorProductVersions
canonicalubuntu-pro-client0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
canonicallinuxcert_advisory90%

References

  • https://ubuntu.com/security/CVE-2026-11386(vdb-entry)

Related News (2 articles)

Tier B
BSI Advisories26d ago
[NEU] [hoch] Ubuntu Linux (ubuntu-pro-client): Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB27d ago
CVE-2026-11386 | Canonical ubuntu-pro-client APT Source File Generation ubuntu-.list str.format directives.aptURL/suites[]/additionalPackages[] input validation
→ No new info (linked only)
CVSS 3.19.0 CRITICAL
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
37.337.2ubuntu0.137.2ubuntu~24.04.137.2ubuntu~22.04.137.1ubuntu0~20.04.137.1ubuntu0~18.04.137.1ubuntu0~16.04.119.7ubuntu0.1
CWECWE-20
PublishedJul 16, 2026
Trending Score3
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-45893EXP
apparmor: Fix & Optimize table creation from possibly unaligned memory
Trending: 9
HIGHCVE-2026-8933
snap-confine Local Privilege Escalation via Capabilities Misconfiguration or Flaw in Execution Environment Setup
Trending: 8
HIGHCVE-2026-15226
snapd snap-confine Sandbox Confinement Bypass via Omission of setuid Restriction in Seccomp Templates
Trending: 4
MEDIUMCVE-2024-5300
AppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via systemd-userdbd
Trending: 3
MEDIUMCVE-2026-9494
ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command Line
Trending: 2

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 16, 2026
Discovered by ZDM
Jul 16, 2026
Patch Available
Jul 16, 2026