Canonical Ubuntu Pro Client Information Disclosure Vulnerability

Vulnerability

A vulnerability allowing information disclosure exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). This issue arises because the client validates Ubuntu Pro APT credentials by executing a command that embeds the secret bearer token directly into the cleartext URL of the command-line arguments. On systems with a default-mounted /proc file system and no process-hiding mitigations, an unprivileged local attacker can read the sensitive token from the process command line of the running helper process. This leaked token could then be used to access the victim's Ubuntu Pro or Expanded Security Maintenance (ESM) repositories without authorization.

Impact

Exploitation of this vulnerability allows an unprivileged local attacker to access sensitive bearer tokens, which can be used to gain unauthorized access to Ubuntu Pro or ESM repositories.

Added: Jul 16, 2026, 1:26 PM
Updated: Jul 16, 2026, 1:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
2.3
remediation
0.0
relevance
9.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.