CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-61897

unknowncovered by 2 sourcesfirst seen 2026-07-21
USN-8580-1 fixed vulnerabilities in AccountsService. This update provides the corresponding fixes for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that the Ubuntu-specific SetLanguage patch to AccountsService incorrectly handled dropping privileges. A local attacker could use this issue to execute arbitrary commands as an administrator. (CVE-2026-61897) It was discovered that the Ubuntu-specific SetLanguage helpers for AccountsService incorrectly handled parsing configuration files. A local attacker could use this issue to execute arbitrary commands. (CVE-2026-61898)

CSIRTS triage

vendor: Ubuntuproduct: AccountsServicePrivilege escalationaffected: Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS
What
Local attackers can execute arbitrary commands as an administrator due to privilege handling issues.
Who is affected
Users of AccountsService on the specified Ubuntu versions are affected.
Urgency
Remediation is critical as it allows local privilege escalation.
Action
Apply the latest updates for AccountsService on affected Ubuntu versions.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-61897

Get an email if CVE-2026-61897 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (2)

External references

NVD record for CVE-2026-61897

CVE.org record

Embed the live status

CVE-2026-61897 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-61897 status](https://www.csirts.com/badge/CVE-2026-61897)](https://www.csirts.com/cve/CVE-2026-61897)