ESC
Type to search CVEs in real-time
Enter open Esc close Ctrl K toggle

CVE-2026-9494

MEDIUM Export PDF

An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools)

An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL component passed via the command-line arguments (argv), resulting in a URL format such as https://bearer:<token>@esm.ubuntu.com/.../. On systems utilizing a default-mounted /proc file system where process-hiding mitigations (such as hidepid) are disabled, an unprivileged local attacker can monitor system processes and read the sensitive bearer token directly from /proc/cmdline while the helper process is actively running. This leaked token can subsequently be used to gain unauthorized access to the victim's Ubuntu Pro or Expanded Security Maintenance (ESM) repositories.

CVSS Score
5.5
MEDIUM
Published
16 Jul 2026 13:16
Modified
16 Jul 2026 16:19
Source
CIRCL

CVSS v3 Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Local
Complexity
Low
Privileges
Low
Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Weaknesses (CWE)

CWE-214

Affected Systems

No vendor data available.

KEV Status

Not in CISA KEV catalog