Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Ubuntu USN |
USN-8580-1 | AccountsService vulnerabilities |
Ubuntu USN |
USN-8580-2 | AccountsService vulnerabilities |
Wed, 26 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Aug 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 20 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical accountsservice |
|
| Vendors & Products |
Canonical
Canonical accountsservice |
Thu, 20 Aug 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject a sed 'e' flag and arbitrary shell commands that execute with the privileges of the AccountsService helper process (real UID 0) via the SetLanguage D-Bus method. | |
| Title | accountsservice: shell injection via attacker-controlled ~/.pam_environment in Ubuntu language helper scripts | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-08-26T19:50:34.552Z
Reserved: 2026-07-11T18:43:51.251Z
Link: CVE-2026-61898
Updated: 2026-08-26T19:50:26.474Z
Status : Awaiting Analysis
Published: 2026-08-20T15:17:38.913
Modified: 2026-08-28T15:24:38.600
Link: CVE-2026-61898
OpenCVE Enrichment
Updated: 2026-08-20T21:15:05Z
Ubuntu USN