ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injection and Remote Code Execution
Summary
| CVE | CVE-2026-11386 |
|---|---|
| State | PUBLISHED |
| Assigner | canonical |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-16 13:16:24 UTC |
| Updated | 2026-07-16 14:16:48 UTC |
| Description | An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\n) characters can successfully inject arbitrary, attacker-controlled deb configuration lines into root-owned APT sources. When combined with the unvalidated additionalPackages[] field—which is passed positionally into a root-executed apt-get install command—an attacker capable of spoofing or manipulating the contract response (e.g., via a compromised internal infrastructure, an intercepted connection utilizing a trusted CA, or local logical bugs) can force the client to fetch and install malicious packages. This ultimately leads to arbitrary code execution with root privileges on the affected system. This component is preinstalled on supported Ubuntu Server releases and auto-attaches by default on cloud provider Ubuntu Pro images. |
Risk And Classification
Primary CVSS: v3.1 9 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS: 0.003170000 probability, percentile 0.238380000 (date 2026-07-20)
Problem Types: CWE-20 | CWE-20 CWE-20 Improper input validation
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 9 | CRITICAL | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 9 | CRITICAL | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Canonical | Ubuntu-pro-client Ubuntu-advantage-tools | affected 37.3 python | Linux |
| CNA | Canonical | Ubuntu 26.04 LTS | unaffected 37.2ubuntu0.1 dpkg | Linux |
| CNA | Canonical | Ubuntu 24.04 LTS | unaffected 37.2ubuntu~24.04.1 dpkg | Linux |
| CNA | Canonical | Ubuntu 22.04 LTS | unaffected 37.2ubuntu~22.04.1 dpkg | Linux |
| CNA | Canonical | Ubuntu 20.04 LTS | unaffected 37.1ubuntu0~20.04.1 dpkg | Linux |
| CNA | Canonical | Ubuntu 18.04 LTS | unaffected 37.1ubuntu0~18.04.1 dpkg | Linux |
| CNA | Canonical | Ubuntu 16.04 LTS | unaffected 37.1ubuntu0~16.04.1 dpkg | Linux |
| CNA | Canonical | Ubuntu 14.04 LTS | unaffected 19.7ubuntu0.1 dpkg | Linux |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ubuntu.com/security/CVE-2026-11386 | [email protected] | ubuntu.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Frederick Jerusha (en)
There are currently no legacy QID mappings associated with this CVE.