CVE-2026-102371
Last modified
CVE-2026-102371 is a medium-severity vulnerability rated 5.7/10 on the CVSS scale. In wsl-pro-service before 0.1.19ubuntu3, the service component which runs as root inside each WSL instance attaches the instance to Ubuntu Pro by executing the pro client with the Ubuntu Pro token passed as a command-line argument (pro attach <token>). On systems where /proc is mounted without process-hiding mitigations (such as hidepid), which is the default in WSL, an unprivileged local user or process in the same WSL instance can read the token from /proc/<pid>/cmdline while the attach process is running.
Description
In wsl-pro-service before 0.1.19ubuntu3, the service component which runs as root inside each WSL instance attaches the instance to Ubuntu Pro by executing the pro client with the Ubuntu Pro token passed as a command-line argument (pro attach <token>). On systems where /proc is mounted without process-hiding mitigations (such as hidepid), which is the default in WSL, an unprivileged local user or process in the same WSL instance can read the token from /proc/<pid>/cmdline while the attach process is running. The leaked token could then be used to attach other machines to the victim's Ubuntu Pro subscription and gain unauthorized access to Ubuntu Pro services.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Ubuntu Pro for WSL | >= 0.1.1, < 0.1.19ubuntu2; >= 0.1.1, < 0.1.18~24.04.3; >= 0.1.1, < 0.1.18~22.04.2; >= 0.1.1, < 0.1.18~20.04.2 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-102371?
How severe is CVE-2026-102371?
How do I fix CVE-2026-102371?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-102365mall4j through 4.0 fails to enforce authorization checks on …6.5
- CVE-2026-102366mall4j through 4.0 contains an unrestricted file upload vuln…4.4
- CVE-2026-102367mall4j through 4.0 contains an insufficient session expirati…5.4
- CVE-2026-102369Tapo C120 v1 and C200 V5 do not adequately protect login cha…8.7
- CVE-2026-10237A vulnerability was found in SourceCodester Water Billing Ma…4.7
- CVE-2026-102370Kasa EC70 v4 and EC71 v4 do not logically disable the produc…5.4
- CVE-2026-102372GestSup versions before 3.2.61 fail to properly sanitize HTM…6.1
- CVE-2026-102373GestSup versions before 3.2.62 fail to validate ticket owner…6.5
- CVE-2026-102374GestSup versions before 3.2.62 contain a stored cross-site s…6.1
- CVE-2026-102375Subscriber Broken Access Control in Optimole <= 4.2.14 versi…6.5
- CVE-2026-102376Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 ve…7.1
- CVE-2026-102377Contributor PHP Object Injection in Photo Gallery by 10Web <…8.8
Are you affected by CVE-2026-102371?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
