{"id":"UBUNTU-CVE-2026-9494","details":"An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL component passed via the command-line arguments (argv), resulting in a URL format such as https://bearer:\u003ctoken\u003e@esm.ubuntu.com/.../. On systems utilizing a default-mounted /proc file system where process-hiding mitigations (such as hidepid) are disabled, an unprivileged local attacker can monitor system processes and read the sensitive bearer token directly from /proc/cmdline while the helper process is actively running. This leaked token can subsequently be used to gain unauthorized access to the victim's Ubuntu Pro or Expanded Security Maintenance (ESM) repositories.","modified":"2026-07-29T10:18:13.552111273Z","published":"2026-07-17T14:00:00Z","related":["USN-8555-1"],"upstream":["CVE-2026-9494"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-9494"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-9494"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8555-1"}],"affected":[{"package":{"name":"ubuntu-advantage-tools","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/ubuntu-advantage-tools?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"37.2ubuntu~22.04.1"}]}],"versions":["27.2.2~21.10.1","27.3~21.10.1","27.4~22.04.1","27.4.1~22.04.1","27.4.2~22.04.1","27.5~22.04.1","27.6~22.04.1","27.7~22.04.1","27.8~22.04.1","27.9~22.04.1","27.10.1~22.04.1","27.11.2~22.04.1","27.11.3~22.04.1","27.12~22.04.1","27.13.1~22.04.1","27.13.2~22.04.1","27.13.3~22.04.1","27.13.5~22.04.1","27.13.6~22.04.1","27.14.4~22.04","28.1~22.04","29.4~22.04","30~22.04","31.2~22.04","31.2.2~22.04","31.2.3~22.04","32.3~22.04","32.3.1~22.04","33.2~22.04","34~22.04","35.1ubuntu0~22.04","36ubuntu0~22.04","37.1ubuntu0~22.04","37.2ubuntu~22.04"],"ecosystem_specific":{"binaries":[{"binary_name":"ubuntu-advantage-pro","binary_version":"37.2ubuntu~22.04.1"},{"binary_name":"ubuntu-advantage-tools","binary_version":"37.2ubuntu~22.04.1"},{"binary_name":"ubuntu-pro-auto-attach","binary_version":"37.2ubuntu~22.04.1"},{"binary_name":"ubuntu-pro-client","binary_version":"37.2ubuntu~22.04.1"},{"binary_name":"ubuntu-pro-client-l10n","binary_version":"37.2ubuntu~22.04.1"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-9494.json"}},{"package":{"name":"ubuntu-advantage-tools","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/ubuntu-advantage-tools?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"37.2ubuntu~24.04.1"}]}],"versions":["29.4","30","30.1","31.1","31.2.2","31.2.2build1","31.2.3","32.3~24.04","32.3.1~24.04","33.2~24.04.1","34~24.04","35.1ubuntu0~24.04","36ubuntu0~24.04","37.1ubuntu0~24.04","37.2ubuntu~24.04"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"ubuntu-advantage-pro","binary_version":"37.2ubuntu~24.04.1"},{"binary_version":"37.2ubuntu~24.04.1","binary_name":"ubuntu-advantage-tools"},{"binary_name":"ubuntu-pro-auto-attach","binary_version":"37.2ubuntu~24.04.1"},{"binary_version":"37.2ubuntu~24.04.1","binary_name":"ubuntu-pro-client"},{"binary_name":"ubuntu-pro-client-l10n","binary_version":"37.2ubuntu~24.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-9494.json"}},{"package":{"name":"ubuntu-advantage-tools","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/ubuntu-advantage-tools?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["35","35.1ubuntu0","36ubuntu0","37ubuntu0","37.1ubuntu0~25.10","37.2ubuntu~25.10"],"ecosystem_specific":{"binaries":[{"binary_name":"ubuntu-advantage-pro","binary_version":"37.2ubuntu~25.10"},{"binary_name":"ubuntu-advantage-tools","binary_version":"37.2ubuntu~25.10"},{"binary_name":"ubuntu-pro-auto-attach","binary_version":"37.2ubuntu~25.10"},{"binary_version":"37.2ubuntu~25.10","binary_name":"ubuntu-pro-client"},{"binary_name":"ubuntu-pro-client-l10n","binary_version":"37.2ubuntu~25.10"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-9494.json"}},{"package":{"name":"ubuntu-advantage-tools","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/ubuntu-advantage-tools?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"37.2ubuntu0.1"}]}],"versions":["37ubuntu0","37.1ubuntu0","37.2ubuntu"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"37.2ubuntu0.1","binary_name":"ubuntu-advantage-pro"},{"binary_name":"ubuntu-advantage-tools","binary_version":"37.2ubuntu0.1"},{"binary_name":"ubuntu-pro-auto-attach","binary_version":"37.2ubuntu0.1"},{"binary_name":"ubuntu-pro-client","binary_version":"37.2ubuntu0.1"},{"binary_name":"ubuntu-pro-client-l10n","binary_version":"37.2ubuntu0.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-9494.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]}