Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-9494

28
FAUCET Score

An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL component passed via the command-line arguments (argv), resulting in a URL format such as https://bearer:<token>@esm.ubuntu.com/.../. On systems utilizing a default-mounted /proc file system where process-hiding mitigations (such as hidepid) are disabled, an unprivileged local attacker can monitor system processes and read the sensitive bearer token directly from /proc/cmdline while the helper process is actively running. This leaked token can subsequently be used to gain unauthorized access to the victim's Ubuntu Pro or Expanded Security Maintenance (ESM) repositories.

First published: Jul 16, 2026Last modified: Jul 16, 2026

Impacted Technologies

VendorProductVersion(s)CPE
CanonicalUbuntu-Pro-Client (Ubuntu-Advantage-Tools)
>= 0, < 37.3CNA affecteddefault unaffected
CanonicalUbuntu 18.04 LTS
Range not provided by sourceCNA affecteddefault affected
CanonicalUbuntu 20.04 LTS
Range not provided by sourceCNA affecteddefault affected
CanonicalUbuntu 22.04 LTS
Range not provided by sourceCNA affecteddefault affected
CanonicalUbuntu 24.04 LTS
Range not provided by sourceCNA affecteddefault affected

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.11%
Probability of exploitation in next 30 days
EPSS Percentile
1.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0011 is in the 10th percentile among its peer group of 15,937 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

ubuntupatch availablevia ubuntu_usn
Product: ubuntu-advantage-tools (bionic)Fixed in: 37.1ubuntu0~18.04.1
ubuntupatch availablevia ubuntu_usn
Product: ubuntu-advantage-tools (focal)Fixed in: 37.1ubuntu0~20.04.1
ubuntupatch availablevia ubuntu_usn
Product: ubuntu-advantage-tools (jammy)Fixed in: 37.2ubuntu~22.04.1
ubuntupatch availablevia ubuntu_usn
Product: ubuntu-advantage-tools (noble)Fixed in: 37.2ubuntu~24.04.1
ubuntupatch availablevia ubuntu_usn
Product: ubuntu-advantage-tools (resolute)Fixed in: 37.2ubuntu0.1
ubuntupatch availablevia ubuntu_usn
Product: ubuntu-advantage-tools (trusty)Fixed in: 19.7ubuntu0.1
ubuntupatch availablevia ubuntu_usn
Product: ubuntu-advantage-tools (xenial)Fixed in: 37.1ubuntu0~16.04.1

Vendor Advisories (1)

ubuntuUSN-8555-1

Ubuntu Advantage Tools (pro client) vulnerabilities

Jul 16, 2026

References

ubuntu.com / security/CVE-2026-9494