# CVE-2026-9494

## Summary

- **CVE ID:** CVE-2026-9494
- **Severity:** MEDIUM
- **CVSS Score:** 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-214
- **Published:** Jul 16, 2026
- **Last Modified:** Jul 16, 2026

## Description

An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in
the cleartext URL component passed via the command-line arguments (argv), resulting in a URL format such as https://bearer:<token>@esm.ubuntu.com/.../. On systems utilizing a default-mounted /proc file system where process-hiding mitigations (such as hidepid) are disabled, an unprivileged local attacker can
monitor system processes and read the sensitive bearer token directly from /proc/cmdline while the helper process is actively running. This leaked token can subsequently be used to gain unauthorized access to the victim's Ubuntu Pro or Expanded Security Maintenance (ESM) repositories.

## Affected Products

- Canonical — ubuntu-pro-client (ubuntu-advantage-tools) (0)
- Canonical — Ubuntu 26.04 LTS (37.2ubuntu0.1)
- Canonical — Ubuntu 24.04 LTS (37.2ubuntu~24.04.1)
- Canonical — Ubuntu 22.04 LTS (37.2ubuntu~22.04.1)
- Canonical — Ubuntu 20.04 LTS (37.1ubuntu0~20.04.1)
- Canonical — Ubuntu 18.04 LTS (37.1ubuntu0~18.04.1)
- Canonical — Ubuntu 16.04 LTS (37.1ubuntu0~16.04.1)
- Canonical — Ubuntu 14.04 LTS (19.7ubuntu0.1)

## References

- [CNA](https://ubuntu.com/security/CVE-2026-9494)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.15%
- **EPSS Percentile:** 4.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-09._