CVE-2026-61897
An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to root, enabling local privilege escalation.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.10%
- CWE
- CWE-273
- Published
- 2026-08-20
- Last modified
- 2026-08-26
Affected products
- Canonical accountsservice
- Canonical accountsservice
- Canonical accountsservice
- Canonical accountsservice
Weakness type
Related vulnerabilities
- CVE-2026-58089 — hwpmc fails to detach PMCs during exec credential transitions
- CVE-2026-58086 — ktrace(2) privilege incorrectly validated in jails
- CVE-2026-49421 — unlinkat(2) ignores AT_RESOLVE_BENEATH flag
- CVE-2026-54552 — sh _uid does not drop supplementary groups (incomplete privilege drop)
- CVE-2026-60085 — PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandbox
- CVE-2026-44073 — seteuid failure ignored in auth modules
- CVE-2026-32107 — xrdp: Fail-open privilege drop in sesexec — child processes may execute as root if setuid fails
- CVE-2026-21882 — theshit's Improper Privilege Dropping Allows Local Privilege Escalation via Command Re-execution