CVE-2025-7044: Canonical Maas

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user.update websocket request and inject the is_superuser property set to true. The server improperly validates this input, allowing the attacker to self-promote to an administrator role. This results in full administrative control over the MAAS deployment.

Affected products

  • Canonical Maas: from 3.3.0, before 3.3.11 (fixed in 3.3.11); from 3.4.0, before 3.4.9 (fixed in 3.4.9); from 3.5.0, before 3.5.9 (fixed in 3.5.9); from 3.6.0, before 3.6.2 (fixed in 3.6.2)

Published 2025-12-03. Last modified 2026-06-17.