CVE-2026-12249
Canonical Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS 취약점
An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Services (AD CS) certificate auto-enrollment via the vendored Samba client script (internal/policies/certificate/python/vendor_samba/gp/gp_cert_auto_enroll_ext.py), ADSys utilizes a plaintext HTTP connection (http://) instead of a secure HTTPS connection (https://) to request the CA certificate from the Active Directory Certificate Services server (GetCACert). An unauthenticated network attacker positioned between the managed Ubuntu host and the configured AD CS CA hostname can...
- 대응 우선순위
- 점검
- CVSS
- 9
- EPSS
- 0.14% 백분위 4.07% · 2026.08.01 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.06.23