Canonical Ubuntu Pro Client Insecure Symlink Vulnerability in Log Collection Command

Vulnerability

A vulnerability allowing insecure symlink following has been identified in Canonical Ubuntu Pro Client (formerly Ubuntu Advantage Tools) within the 'pro collect-logs' command framework. This issue arises because the utility creates or uses predictable temporary file paths or user-accessible log directories for gathering diagnostic information, without verifying the file type or ownership. An unprivileged local attacker can exploit this by creating a symbolic link at a predictable destination that points to an arbitrary, root-readable file, such as '/etc/shadow' or private files in '/root'. When a root administrator executes the 'pro collect-logs' command, the tool follows the symlink, reads the target file, and compresses its contents into a diagnostic support archive. Since the output archive is accessible to the unprivileged user, the attacker can extract and read the sensitive root-owned files, resulting in complete information disclosure of system secrets.

Impact

Exploitation of this vulnerability leads to unauthorized access to sensitive root-owned files, such as those containing password hashes or private information, allowing for a complete disclosure of system secrets.

Added: Jul 16, 2026, 1:30 PM
Updated: Jul 16, 2026, 1:30 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.0
remediation
0.0
relevance
9.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.