CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-61898

highCVSS 7.8covered by 3 sourcesfirst seen 2026-07-21
The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject a sed 'e' flag and arbitrary shell commands that execute with the privileges of the AccountsService helper process (real UID 0) via the SetLanguage D-Bus method.

CSIRTS triage

vendor: Ubuntuproduct: AccountsServicePrivilege escalationaffected: Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS
What
Local attackers can execute arbitrary commands as an administrator due to privilege handling issues.
Who is affected
Users of AccountsService on the specified Ubuntu versions are affected.
Urgency
Remediation is critical as it allows local privilege escalation.
Action
Apply the latest updates for AccountsService on affected Ubuntu versions.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-61898

Get an email if CVE-2026-61898 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (3)

External references

NVD record for CVE-2026-61898

CVE.org record

Embed the live status

CVE-2026-61898 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-61898 status](https://www.csirts.com/badge/CVE-2026-61898)](https://www.csirts.com/cve/CVE-2026-61898)