CVE-2026-61898

EUVD-2026-63380
The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject a sed 'e' flag and arbitrary shell commands that execute with the privileges of the AccountsService helper process (real UID 0) via the SetLanguage D-Bus method.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Debian logo
Debian Releases
Debian Product
Codename
accountsservice
bookworm
22.08.8-6
fixed
bullseye
0.6.55-3
fixed
forky
23.13.9-8
fixed
sid
23.13.9-8
fixed
trixie
23.13.9-7
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
accountsservice
bionic
Fixed 0.6.45-1ubuntu1.3+esm2
released
focal
Fixed 0.6.55-0ubuntu12~20.04.7+esm1
released
jammy
Fixed 22.07.5-2ubuntu1.6
released
noble
Fixed 23.13.9-2ubuntu6.1
released
resolute
Fixed 23.13.9-8ubuntu5.2
released
trusty
Fixed 0.6.35-0ubuntu7.3+esm4
released
xenial
Fixed 0.6.40-2ubuntu11.6+esm2
released