Search
Find a vulnerability
Search criteria
2 vulnerabilities found for MAAS by Canonical
CVE-2026-12392 (GCVE-0-2026-12392)
Vulnerability from cvelistv5 – Published: 2026-10-02 19:24 – Updated: 2026-10-03 15:52
VLAI
EPSS
VEX
Title
RPC secret disclosure via vendor data endpoint in Canonical MAAS
Summary
An information exposure vulnerability in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows an unauthenticated attacker to retrieve the RPC secret in plaintext via the vendor data metadata endpoint. If a target machine was deployed with the 'register as rack' option enabled, an attacker who obtains or infers the machine's system ID can query the preseed/metadata server to leak the secret.
Severity
5.3 (Medium)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-03 15:47 UTC
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/canonical/maas/commit/8489979d… | patch |
| https://github.com/canonical/maas/commit/a9486ad0… | patch |
| https://github.com/canonical/maas/commit/ead659f7… | patch |
| https://github.com/canonical/maas/commit/3864ef9d… | patch |
| https://github.com/canonical/maas/commit/65e89c05… | patch |
| https://bugs.launchpad.net/maas/+bug/2153942 | vendor-advisoryissue-tracking |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Canonical | MAAS |
Affected:
3.4.0 , < 3.4.10
(semver)
Affected: 3.5.0 , < 3.5.14 (semver) Affected: 3.6.0 , < 3.6.5 (semver) Affected: 3.7.0 , < 3.7.3 (semver) Affected: 0 , < 3.8.0 (semver) cpe:2.3:a:canonical:maas:*:*:linux:*:*:*:*:* cpe:2.3:a:canonical:maas:*:*:linux:*:*:*:*:* cpe:2.3:a:canonical:maas:*:*:linux:*:*:*:*:* cpe:2.3:a:canonical:maas:*:*:linux:*:*:*:*:* cpe:2.3:a:canonical:maas:*:*:linux:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-12392",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-03T15:47:50.712440Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T15:52:55.367Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "maas",
"platforms": [
"Linux"
],
"product": "MAAS",
"repo": "https://github.com/canonical/maas",
"vendor": "Canonical",
"versions": [
{
"lessThan": "3.4.10",
"status": "affected",
"version": "3.4.0",
"versionType": "semver"
},
{
"lessThan": "3.5.14",
"status": "affected",
"version": "3.5.0",
"versionType": "semver"
},
{
"lessThan": "3.6.5",
"status": "affected",
"version": "3.6.0",
"versionType": "semver"
},
{
"lessThan": "3.7.3",
"status": "affected",
"version": "3.7.0",
"versionType": "semver"
},
{
"lessThan": "3.8.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:canonical:maas:*:*:linux:*:*:*:*:*",
"versionEndExcluding": "3.4.10",
"versionStartIncluding": "3.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:canonical:maas:*:*:linux:*:*:*:*:*",
"versionEndExcluding": "3.5.14",
"versionStartIncluding": "3.5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:canonical:maas:*:*:linux:*:*:*:*:*",
"versionEndExcluding": "3.6.5",
"versionStartIncluding": "3.6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:canonical:maas:*:*:linux:*:*:*:*:*",
"versionEndExcluding": "3.7.3",
"versionStartIncluding": "3.7.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:canonical:maas:*:*:linux:*:*:*:*:*",
"versionEndExcluding": "3.8.0",
"versionStartIncluding": "0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"descriptions": [
{
"lang": "en",
"value": "An information exposure vulnerability in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows an unauthenticated attacker to retrieve the RPC secret in plaintext via the vendor data metadata endpoint. If a target machine was deployed with the \u0027register as rack\u0027 option enabled, an attacker who obtains or infers the machine\u0027s system ID can query the preseed/metadata server to leak the secret."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T19:24:09.110Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/maas/commit/8489979d64b0e7f124e7cef66d02b21263918f9b"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/maas/commit/a9486ad0cc90f4571142c1bea13f02d1361cb31e"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/maas/commit/ead659f70224538517c80478c3fd8c9e730aae79"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/maas/commit/3864ef9dca54e36e3d34d18233b87666b8ee1dc8"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/maas/commit/65e89c05970f4514f9e6de043c2779017b43ad9d"
},
{
"tags": [
"vendor-advisory",
"issue-tracking"
],
"url": "https://bugs.launchpad.net/maas/+bug/2153942"
}
],
"title": "RPC secret disclosure via vendor data endpoint in Canonical MAAS",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-12392",
"datePublished": "2026-10-02T19:24:09.110Z",
"dateReserved": "2026-06-16T12:16:09.502Z",
"dateUpdated": "2026-10-03T15:52:55.367Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2024-6107 (GCVE-0-2024-6107)
Vulnerability from cvelistv5 – Published: 2025-07-21 08:52 – Updated: 2025-07-21 17:07
VLAI
EPSS
VEX
Summary
Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been addressed in MAAS and updated in the corresponding snaps.
Severity
9.6 (Critical)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-07-21 17:06 UTC
CWE
- CWE-287 - When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Assigner
References
1 reference
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-6107",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-07-21T17:06:46.994969Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-07-21T17:07:16.633Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"packageName": "maas",
"platforms": [
"Linux"
],
"product": "MAAS",
"repo": "https://git.launchpad.net/maas/",
"vendor": "Canonical",
"versions": [
{
"lessThan": "3.1.4",
"status": "affected",
"version": "3.1.0",
"versionType": "semver"
},
{
"lessThan": "3.2.11",
"status": "affected",
"version": "3.2.0",
"versionType": "semver"
},
{
"lessThan": "3.3.8",
"status": "affected",
"version": "3.3.0",
"versionType": "semver"
},
{
"lessThan": "3.4.4",
"status": "affected",
"version": "3.4.0",
"versionType": "semver"
},
{
"lessThan": "3.5.1",
"status": "affected",
"version": "3.5.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been addressed in MAAS and updated in the corresponding snaps."
}
],
"impacts": [
{
"descriptions": [
{
"lang": "en",
"value": "This vulnerability allows attackers with a malicious client to execute RPC commands on the region without authentication."
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.6,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-07-21T08:52:56.608Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"url": "https://bugs.launchpad.net/maas/+bug/2069094"
}
],
"source": {
"discovery": "INTERNAL"
}
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2024-6107",
"datePublished": "2025-07-21T08:52:56.608Z",
"dateReserved": "2024-06-18T00:31:47.270Z",
"dateUpdated": "2025-07-21T17:07:16.633Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}