Canonical ubuntu-pro-client APT source injection enables root code execution

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2026-11386?

CVE-2026-11386 is a vulnerability classified as Improper Input Validation, affecting ubuntu-pro-client (ubuntu-advantage-tools) (affected versions: < 37.3), Ubuntu 26.04 LTS, Ubuntu 24.04 LTS, and 5 more products. This vulnerability is rated Critical, with a CVSS score of 9. Current sources do not report this vulnerability as exploited.

Overview

Original source data

An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\n) characters can successfully inject arbitrary, attacker-controlled deb configuration lines into root-owned APT sources. When combined with the unvalidated additionalPackages[] field—which is passed positionally into a root-executed apt-get install command—an attacker capable of spoofing or manipulating the contract response (e.g., via a compromised internal infrastructure, an intercepted connection utilizing a trusted CA, or local logical bugs) can force the client to fetch and install malicious packages. This ultimately leads to arbitrary code execution with root privileges on the affected system. This component is preinstalled on supported Ubuntu Server releases and auto-attaches by default on cloud provider Ubuntu Pro images.

Affected products and scope

  • Canonical ubuntu-pro-client: versions less than 37.3 are marked affected.
  • Ubuntu 26.04 LTS with ubuntu-advantage-tools: affected by default; Canonical lists 37.2ubuntu0.1 as the fixed package version.
  • Ubuntu 24.04 LTS: fixed in 37.2ubuntu~24.04.1.
  • Ubuntu 22.04 LTS: fixed in 37.2ubuntu~22.04.1.
  • Ubuntu 20.04 LTS: fixed in 37.1ubuntu0~20.04.1, available through Ubuntu Pro.
  • Ubuntu 18.04 LTS: fixed in 37.1ubuntu0~18.04.1, available through Ubuntu Pro.
  • Ubuntu 16.04 LTS: fixed in 37.1ubuntu0~16.04.1, available through Ubuntu Pro with the Legacy Support add-on.
  • Ubuntu 14.04 LTS: the initial fix was listed as 19.7ubuntu0.1, but a later Canonical regression notice specifies 19.7ubuntu0.2; the later target should be used.
  • Ubuntu 25.10 is marked Ignored by Canonical because it is end of life; the checked status information does not provide a supported fixed boundary for that branch.

Technical details

Canonical ubuntu-pro-client uses contract server data to construct APT source files. The directives.suites[] and directives.aptURL fields are written with Python str.format() without escaping, validation, or newline filtering, so data containing newline characters can inject attacker-controlled deb configuration lines into root-owned APT sources.

The additionalPackages[] field is also insufficiently validated and is passed positionally to a root-executed apt-get install command. If an attacker can spoof or manipulate the contract response, the client may fetch and install malicious packages after the APT sources have been altered.

The documented preconditions include compromised internal infrastructure, an intercepted connection using a trusted CA, or local logical bugs. Public detail does not identify the exact call path that processes the response or provide a specific exploit payload.

Exploitability

The vulnerability is reachable through the network when an attacker can spoof or modify the contract server response. The record describes high attack complexity, no required authentication privileges, and no user interaction, but control or interference with the response is a material precondition.

The supplied record marks public exploit as false and does not provide a known exploitation status. That absence should not be interpreted as proof that exploitation has not occurred. Ubuntu describes the possible result as arbitrary APT configuration injection followed by arbitrary code execution.

Technical impact

An attacker can inject arbitrary APT source lines into files owned by root and then use the additional package field to make the client invoke apt-get install with attacker-controlled values. The documented outcome is arbitrary code execution with root privileges, with impact extending beyond the original contract-processing context.

Possible consequences include control of system software and configuration, access to data readable by root, unauthorized data modification, or service disruption. The requirement to control or interfere with the contract response makes this more demanding than a simple unauthenticated network request, and the available evidence does not confirm a specific exploit or observed exploitation.

Business impact

If exploited, the client can write attacker-controlled APT configuration and trigger package installation with root privileges. Malicious packages could then cause loss of confidentiality, integrity, and availability, including possible changes to system software or disruption of services.

The exposure is particularly relevant to supported Ubuntu Server installations where the component is preinstalled and to cloud provider Ubuntu Pro images where it auto-attaches by default. The record does not confirm a specific compromise, victim, or campaign.

Remediation

  1. Update ubuntu-advantage-tools or ubuntu-pro-client to the branch-specific fixed package. Canonical lists 37.2ubuntu0.1 for Ubuntu 26.04 LTS, 37.2ubuntu~24.04.1 for Ubuntu 24.04 LTS, 37.2ubuntu~22.04.1 for Ubuntu 22.04 LTS, 37.1ubuntu0~20.04.1 for Ubuntu 20.04 LTS, 37.1ubuntu0~18.04.1 for Ubuntu 18.04 LTS, and 37.1ubuntu0~16.04.1 for Ubuntu 16.04 LTS.
  2. On Ubuntu 14.04 LTS, update to 19.7ubuntu0.2. The later regression notice identifies this package version for the branch and supersedes the initially listed 19.7ubuntu0.1 target.
  3. Verify the installed package version after updating on both conventional Ubuntu Server systems and cloud images with Ubuntu Pro auto-attach. Do not infer the status of another branch merely because one branch has been fixed.
  4. If Ubuntu 25.10 is still deployed, migrate to a supported release because Canonical marks that branch end of life and the checked information does not provide a supported fixed boundary.
  5. Until updates can be applied, restrict and monitor connectivity to the contract server, validate response integrity, and review APT source changes. These are precautionary measures and do not replace the confirmed package updates.

Detection

  1. Inventory Ubuntu Server systems and cloud images running ubuntu-pro-client or ubuntu-advantage-tools, then compare installed package versions with the branch-specific fixes listed in remediation.
  2. Inspect files under /etc/apt/sources.list.d/, especially files generated by Ubuntu Pro, and the corresponding DEB822 APT sources for unexpected repository lines or changes outside the approved administration process.
  3. Review the provenance and integrity of contract server responses consumed by the client, particularly values associated with directives.suites[], directives.aptURL, and additionalPackages[].
  4. Correlate APT source changes and package installation activity with Ubuntu Pro client executions. This is precautionary monitoring because the public sources do not define specific log events or IOCs, and the absence of suspicious log evidence does not prove that a system is safe.
Sources (17)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan