Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4989 articles · 189008 vulns · 37/41 feeds (7d)
← Back to list
5.5
CVE-2026-9494PATCHED
canonical · ubuntu-pro-client (ubuntu-advantage-tools)

ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command Line

Description

An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL component passed via the command-line arguments (argv), resulting in a URL format such as https://bearer:<token>@esm.ubuntu.com/.../. On systems utilizing a default-mounted /proc file system where process-hiding mitigations (such as hidepid) are disabled, an unprivileged local attacker can monitor system processes and read the sensitive bearer token directly from /proc/cmdline while the helper process is actively running. This leaked token can subsequently be used to gain unauthorized access to the victim's Ubuntu Pro or Expanded Security Maintenance (ESM) repositories.

Affected Products

VendorProductVersions
canonicalubuntu-pro-client (ubuntu-advantage-tools)0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
canonicallinuxcert_advisory90%

References

  • https://ubuntu.com/security/CVE-2026-9494(vdb-entry)

Related News (2 articles)

Tier B
BSI Advisories26d ago
[NEU] [hoch] Ubuntu Linux (ubuntu-pro-client): Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB27d ago
CVE-2026-9494 | Canonical ubuntu-pro-client Credentials Validation /usr/lib/apt/apt-helper download-file missing encryption
→ No new info (linked only)
CVSS 3.15.5 MEDIUM
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
37.337.2ubuntu0.137.2ubuntu~24.04.137.2ubuntu~22.04.137.1ubuntu0~20.04.137.1ubuntu0~18.04.137.1ubuntu0~16.04.119.7ubuntu0.1
CWECWE-214
PublishedJul 16, 2026
Trending Score2
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-45893EXP
apparmor: Fix & Optimize table creation from possibly unaligned memory
Trending: 9
HIGHCVE-2026-8933
snap-confine Local Privilege Escalation via Capabilities Misconfiguration or Flaw in Execution Environment Setup
Trending: 8
HIGHCVE-2026-15226
snapd snap-confine Sandbox Confinement Bypass via Omission of setuid Restriction in Seccomp Templates
Trending: 4
CRITICALCVE-2026-11386
ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injection and Remote Code Execution
Trending: 3
MEDIUMCVE-2024-5300
AppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via systemd-userdbd
Trending: 3

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 16, 2026
Discovered by ZDM
Jul 16, 2026
Patch Available
Jul 16, 2026