CVE-2026-61898: Canonical Accountsservice
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject a sed 'e' flag and arbitrary shell commands that execute with the privileges of the AccountsService helper process (real UID 0) via the SetLanguage D-Bus method.
Affected products
- Canonical Accountsservice: from 22.07.5-2ubuntu1, before 22.07.5-2ubuntu1.6 (fixed in 22.07.5-2ubuntu1.6); from 23.13.9-2ubuntu6, before 23.13.9-2ubuntu6.1 (fixed in 23.13.9-2ubuntu6.1); from 23.13.9-8ubuntu5, before 23.13.9-8ubuntu5.2 (fixed in 23.13.9-8ubuntu5.2); from 23.13.9-8ubuntu6, before 23.13.9-8ubuntu7 (fixed in 23.13.9-8ubuntu7)
Published 2026-08-20. Last modified 2026-08-28.