All 3 CVE vulnerabilities found in ubuntu-pro-client (ubuntu-advantage-tools), with AI-generated Chinese analysis, references, and POCs.
Vendor: Canonical
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-12391 | ubuntu-pro-client Local Privilege Escalation and Information Disclosure via Symlink Arbitrary File Read in collect-logs CWE-59 | 5.0 | Medium | 2026-07-16 |
| CVE-2026-11386 | ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injection and Remote Code Execution CWE-20 | 9.0 | Critical | 2026-07-16 |
| CVE-2026-9494 | ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command Line CWE-214 | 5.5 | Medium | 2026-07-16 |
All 3 known CVE vulnerabilities affecting ubuntu-pro-client (ubuntu-advantage-tools) with full Chinese analysis, references, and POCs where available.