CVE-2026-61898: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Canonical accountsservice
Description
CVE-2026-61898 is an OS command injection vulnerability in Canonical's accountsservice affecting certain Ubuntu-specific language helper scripts. The vulnerability arises because these scripts treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input and interpolate it unescaped into a GNU sed replacement expression. This allows an attacker to inject arbitrary shell commands executed with root privileges via the SetLanguage D-Bus method. The issue affects multiple specific versions of accountsservice prior to 23.13.9-8ubuntu7. The vulnerability has a high severity score of 7.8 CVSS v3.1.
CVSS v3.1
Score 7.8high
Affected software
Canonical
accountsservice
pkg:deb/ubuntu/accountsserviceRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists in Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before version 23.13.9-8ubuntu7. These scripts improperly handle the user-controlled LANGUAGE environment variable from ~/.pam_environment by interpolating it unescaped into a GNU sed replacement expression. This improper neutralization of special elements (CWE-78) enables an attacker to inject a sed 'e' flag and arbitrary shell commands. These commands execute with the privileges of the AccountsService helper process, which runs as root (UID 0), via the SetLanguage D-Bus method. The vulnerability is confirmed in multiple specific package versions of accountsservice on Ubuntu.
Potential Impact
Successful exploitation allows an attacker with limited privileges to execute arbitrary shell commands with root privileges on the affected system. This can lead to full system compromise, including confidentiality, integrity, and availability impacts. The CVSS v3.1 base score is 7.8, reflecting high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
The vulnerability affects accountsservice versions prior to 23.13.9-8ubuntu7. Users should upgrade to version 23.13.9-8ubuntu7 or later where this issue is fixed. Since the vendor advisory content is not explicitly provided here, patch status is inferred from the version range indicating fixed in 23.13.9-8ubuntu7. No additional mitigation steps are indicated. Users should apply the official update from Canonical to remediate this vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- canonical
- Date Reserved
- 2026-07-11T18:43:51.251Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a871151acd9273b49bdeee6
Added to database: 08/20/2026, 14:38:09 UTC
Last enriched: 09/10/2026, 23:47:26 UTC
Last updated: 10/04/2026, 16:08:40 UTC
Views: 66
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.