Junglewise Threat Intelligence

CVE-2026-9494: Canonical ubuntu-pro-client information disclosure via process arguments

CVE-2026-9494 · Severity: medium · CVSS 5.5 · Published 2026-07-16

Technologies: Canonical Ubuntu 20.04 LTS, Canonical Ubuntu 24.04 LTS, Canonical Ubuntu-Pro-Client. Vendors: Canonical.

Executive brief

A security flaw in the Ubuntu Pro client could allow a local user to steal sensitive authentication tokens. This client is used to manage premium support and security updates on Ubuntu systems. If exploited, an attacker could gain unauthorized access to the victim's private software repositories and security maintenance services.

Technical details

An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) due to the insecure handling of credentials. When validating Ubuntu Pro APT credentials, the client executes /usr/lib/apt/apt-helper and passes the secret bearer token as a cleartext component of a URL in the command-line arguments (argv). On systems where process-hiding mitigations like 'hidepid' are not enabled, a local unprivileged attacker can read these arguments from /proc/cmdline while the process is running. This allows the attacker to capture the token and gain unauthorized access to Ubuntu Pro or Expanded Security Maintenance (ESM) repositories. The issue is addressed in ubuntu-pro-client version 37.3 and corresponding package updates for various Ubuntu LTS releases.

Affected products

  • Canonical ubuntu-pro-client < 37.3
  • Canonical Ubuntu 26.04 LTS < 37.2ubuntu0.1
  • Canonical Ubuntu 24.04 LTS < 37.2ubuntu~24.04.1
  • Canonical Ubuntu 22.04 LTS < 37.2ubuntu~22.04.1
  • Canonical Ubuntu 20.04 LTS < 37.1ubuntu0~20.04.1

Timeline

  • 2026-07-16: disclosed
  • 2026-07-16: advisory

References

Related threats