LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-11386

Published
CVSS9
Severitycritical
WeaknessCWE-20
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Description

An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\n) characters can successfully inject arbitrary, attacker-controlled deb configuration lines into root-owned APT sources. When c

References

← Back to the CVE Tracker

Our coverage of CVE-2026-11386

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-11386.