Review reviewCritical

CVE-2026-11386

Canonical ubuntu-pro-client (ubuntu-advantage-tools), Ubuntu 26.04 LTS, Ubuntu 24.04 LTS

An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\n) characters can success...

CVSS
9
EPSS
0.34%
26.9% percentile
CISA KEV
Not listed
Published
2026.07.16
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.34%
Technical severityCVSS 9

Vulnerability overview

An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\n) characters can success...

Affected product and versions

Product
Canonical ubuntu-pro-client (ubuntu-advantage-tools), Ubuntu 26.04 LTS, Ubuntu 24.04 LTS
Affected versions
< 37.3
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Canonical ubuntu-pro-client (ubuntu-advantage-tools), Ubuntu 26.04 LTS, Ubuntu 24.04 LTS and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE
CWE-20
CVE-2026-11386 — Canonical ubuntu-pro-client (ubuntu-advantage-tools), Ubuntu 26.04 LTS, Ubuntu 24.04 LTS | SECUFOCUS NOW