CVE-2026-11386
Last modified
CVE-2026-11386 is a critical-severity vulnerability rated 9/10 on the CVSS scale. An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields.
Description
An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\n) characters can successfully inject arbitrary, attacker-controlled deb configuration lines into root-owned APT sources. When combined with the unvalidated additionalPackages[] field—which is passed positionally into a root-executed apt-get install command—an attacker capable of spoofing or manipulating the contract response (e.g., via a compromised internal infrastructure, an intercepted connection utilizing a trusted CA, or local logical bugs) can force the client to fetch and install malicious packages. This ultimately leads to arbitrary code execution with root privileges on the affected system. This component is preinstalled on supported Ubuntu Server releases and auto-attaches by default on cloud provider Ubuntu Pro images.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Canonical | ubuntu-pro-client (ubuntu-advantage-tools) | < 37.3 |
| Canonical | Ubuntu 26.04 LTS | All versions |
| Canonical | Ubuntu 24.04 LTS | All versions |
| Canonical | Ubuntu 22.04 LTS | All versions |
| Canonical | Ubuntu 20.04 LTS | All versions |
| Canonical | Ubuntu 18.04 LTS | All versions |
| Canonical | Ubuntu 16.04 LTS | All versions |
| Canonical | Ubuntu 14.04 LTS | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Undergoing Analysis
Frequently Asked Questions
What is CVE-2026-11386?
How severe is CVE-2026-11386?
How do I fix CVE-2026-11386?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-11373Net::Statsite::Client versions through 1.1.0 for Perl allow …9.1
- CVE-2026-11374In ManageEngine ADSelfService Plus, RecoveryManager Plus, M3…9
- CVE-2026-11379GitLab has remediated an issue in GitLab EE affecting all ve…5.3
- CVE-2026-1138A flaw has been found in UTT 进取 520W 1.7.7-180627. This affe…8.8
- CVE-2026-11380The JetWidgets For Elementor plugin for WordPress is vulnera…6.4
- CVE-2026-11383IBM Tivoli System Automation Application Manager 4.1 and IBM…5.4
- CVE-2026-11387The SMS Alert – SMS & OTP for WooCommerce, Order Notificatio…9.8
- CVE-2026-1139A vulnerability has been found in UTT 进取 520W 1.7.7-180627. …8.8
- CVE-2026-11390The News Kit Addons For Elementor plugin for WordPress is vu…6.4
- CVE-2026-11391Tanium addressed a SQL injection vulnerability in Patch.6.3
- CVE-2026-11392The WP Hotel Booking plugin for WordPress is vulnerable to R…6.1
- CVE-2026-11393Improper neutralization of triple-quote characters during Py…9
Are you affected by CVE-2026-11386?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
