CVE-2026-12392: Canonical Maas

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

An information exposure vulnerability in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows an unauthenticated attacker to retrieve the RPC secret in plaintext via the vendor data metadata endpoint. If a target machine was deployed with the 'register as rack' option enabled, an attacker who obtains or infers the machine's system ID can query the preseed/metadata server to leak the secret.

Affected products

  • Canonical Maas: from 3.4.0, before 3.4.10 (fixed in 3.4.10); from 3.5.0, before 3.5.14 (fixed in 3.5.14); from 3.6.0, before 3.6.5 (fixed in 3.6.5); from 3.7.0, before 3.7.3 (fixed in 3.7.3); before 3.8.0 (fixed in 3.8.0)

Published 2026-10-02. Last modified 2026-10-06.