7.8
CVE-2026-61898
- EPSS -
- Veröffentlicht 20.08.2026 14:32:59
- Zuletzt bearbeitet 20.08.2026 15:17:38
- CVE-Watchlists
- Unerledigt
accountsservice: shell injection via attacker-controlled ~/.pam_environment in Ubuntu language helper scripts
The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject a sed 'e' flag and arbitrary shell commands that execute with the privileges of the AccountsService helper process (real UID 0) via the SetLanguage D-Bus method.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerCanonical
≫
Produkt
accountsservice
Default Statusunaffected
Version
22.07.5-2ubuntu1
Version <
22.07.5-2ubuntu1.6
Status
affected
Version
23.13.9-2ubuntu6
Version <
23.13.9-2ubuntu6.1
Status
affected
Version
23.13.9-8ubuntu5
Version <
23.13.9-8ubuntu5.2
Status
affected
Version
23.13.9-8ubuntu6
Version <
23.13.9-8ubuntu7
Status
affected
VulnDex Vulnerability Enrichment
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Canonical | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
https://bugs.launchpad.net/ubuntu/+source/accountsservice/+bug/2157985
https://ubuntu.com/security/CVE-2026-61898