PT-2026-63318 · Canonical · Accountsservice

CVE-2026-61897

·

Published

2026-07-21

·

Updated

2026-07-21

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
USN-8580-1 fixed vulnerabilities in AccountsService. This update provides the corresponding fixes for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that the Ubuntu-specific SetLanguage patch to AccountsService incorrectly handled dropping privileges. A local attacker could use this issue to execute arbitrary commands as an administrator. (CVE-2026-61897)
It was discovered that the Ubuntu-specific SetLanguage helpers for AccountsService incorrectly handled parsing configuration files. A local attacker could use this issue to execute arbitrary commands. (CVE-2026-61898)
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-61897
USN-8580-1
USN-8580-2

Affected Products

Accountsservice