CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

USN-8580-1: AccountsService vulnerabilities

unknownCVE-2026-61897CVE-2026-61898
It was discovered that the Ubuntu-specific SetLanguage patch to AccountsService incorrectly handled dropping privileges. A local attacker could use this issue to execute arbitrary commands as an administrator. (CVE-2026-61897) It was discovered that the Ubuntu-specific SetLanguage helpers for AccountsService incorrectly handled parsing configuration files. A local attacker could use this issue to execute arbitrary commands. (CVE-2026-61898)

CSIRTS triage

What
Improper handling of privileges allows local attackers to execute arbitrary commands.
Who is affected
Local users of AccountsService on affected Ubuntu systems.
Urgency
Remediation is necessary to prevent local privilege escalation attacks.
Action
Apply the latest updates to AccountsService to fix the vulnerabilities.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch AccountsService

Get an email when a new AccountsService advisory drops — max one per day, one-click unsubscribe.

Details

Source
Ubuntu Security Notices (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-07-21
Exploitation
Not in CISA KEV at last sync

Original advisory: https://ubuntu.com/security/notices/USN-8580-1

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-61897coverage & exploitation statusNVD · CVE.org
CVE-2026-61898coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Ubuntu Security Notices