CVE-2026-9494

EUVD-2026-44910
An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in
the cleartext URL component passed via the command-line arguments (argv), resulting in a URL format such as https://bearer:<token>@esm.ubuntu.com/.../. On systems utilizing a default-mounted /proc file system where process-hiding mitigations (such as hidepid) are disabled, an unprivileged local attacker can
monitor system processes and read the sensitive bearer token directly from /proc/cmdline while the helper process is actively running. This leaked token can subsequently be used to gain unauthorized access to the victim's Ubuntu Pro or Expanded Security Maintenance (ESM) repositories.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 4.21%
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ubuntu-advantage-tools
bionic
Fixed 37.1ubuntu0~18.04.1
released
focal
Fixed 37.1ubuntu0~20.04.1
released
jammy
Fixed 37.2ubuntu~22.04.1
released
noble
Fixed 37.2ubuntu~24.04.1
released
questing
ignored
resolute
Fixed 37.2ubuntu0.1
released
trusty
Fixed 19.7ubuntu0.1
released
xenial
Fixed 37.1ubuntu0~16.04.1
released