========================================================================== Ubuntu Security Notice USN-8580-1 July 21, 2026
accountsservice vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: AccountsService could be made to run programs as an administrator if it opened a specially crafted file. Software Description: - accountsservice: query and manipulate user account information Details: It was discovered that the Ubuntu-specific SetLanguage patch to AccountsService incorrectly handled dropping privileges. A local attacker could use this issue to execute arbitrary commands as an administrator. (CVE-2026-61897) It was discovered that the Ubuntu-specific SetLanguage helpers for AccountsService incorrectly handled parsing configuration files. A local attacker could use this issue to execute arbitrary commands. (CVE-2026-61898) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS accountsservice 23.13.9-8ubuntu5.2 libaccountsservice0 23.13.9-8ubuntu5.2 Ubuntu 24.04 LTS accountsservice 23.13.9-2ubuntu6.1 libaccountsservice0 23.13.9-2ubuntu6.1 Ubuntu 22.04 LTS accountsservice 22.07.5-2ubuntu1.6 libaccountsservice0 22.07.5-2ubuntu1.6 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8580-1 CVE-2026-61897, CVE-2026-61898 Package Information: https://launchpad.net/ubuntu/+source/accountsservice/23.13.9-8ubuntu5.2 https://launchpad.net/ubuntu/+source/accountsservice/23.13.9-2ubuntu6.1 https://launchpad.net/ubuntu/+source/accountsservice/22.07.5-2ubuntu1.6
signature.asc
Description: OpenPGP digital signature
