Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Ubuntu USN |
USN-8580-1 | AccountsService vulnerabilities |
Ubuntu USN |
USN-8580-2 | AccountsService vulnerabilities |
Thu, 20 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical accountsservice |
|
| Vendors & Products |
Canonical
Canonical accountsservice |
Thu, 20 Aug 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject a sed 'e' flag and arbitrary shell commands that execute with the privileges of the AccountsService helper process (real UID 0) via the SetLanguage D-Bus method. | |
| Title | accountsservice: shell injection via attacker-controlled ~/.pam_environment in Ubuntu language helper scripts | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-08-20T14:32:59.924Z
Reserved: 2026-07-11T18:43:51.251Z
Link: CVE-2026-61898
No data.
Status : Received
Published: 2026-08-20T15:17:38.913
Modified: 2026-08-20T15:17:38.913
Link: CVE-2026-61898
No data.
OpenCVE Enrichment
Updated: 2026-08-20T15:45:03Z
Ubuntu USN