Ubuntu AccountsService Vulnerabilities Allow Local Privilege Escalation
Two critical flaws in Ubuntu's AccountsService could let local attackers execute commands as admins. Patches are available for multiple LTS versions.
TL;DR
- CVE-2026-61897: Flaw in SetLanguage patch privilege handling allows command execution as admin.
- CVE-2026-61898: Misconfiguration in SetLanguage helpers leads to arbitrary command execution.
- Affects Ubuntu 14.04, 16.04, 18.04, and 20.04 LTS.
- Patched in USN-8580-1 and extended in USN-8580-2.
- Local attackers can exploit these flaws without network access.
Ubuntu has disclosed two high-severity vulnerabilities in its AccountsService package that could allow local attackers to escalate privileges. These flaws, identified as CVE-2026-61897 and CVE-2026-61898, affect specific Ubuntu Long Term Support (LTS) releases and stem from improper handling in the Ubuntu-specific SetLanguage functionality.
The vulnerabilities enable unprivileged local users to bypass restrictions and execute arbitrary commands with administrative rights. Organizations running affected Ubuntu versions should apply updates immediately to mitigate potential system compromise.
Vulnerability Details
- CVE-2026-61897 involves incorrect privilege dropping in the SetLanguage patch, enabling local command execution as an administrator.
- CVE-2026-61898 arises from improper parsing of configuration files by SetLanguage helpers, allowing arbitrary command execution.
- Both issues are specific to Ubuntu’s modifications of the upstream AccountsService component.
Affected Systems and Fixes
- Impacted releases include Ubuntu 14.04, 16.04, 18.04, and 20.04 LTS.
- Initial fixes were released in USN-8580-1, followed by extended support in USN-8580-2.
- Administrators should update their systems using standard package management tools to deploy the patched AccountsService versions.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.