Critical Vulnerabilities in AccountsService Affect Multiple Ubuntu Versions

Critical Vulnerabilities in AccountsService Affect Multiple Ubuntu Versions

First seen 21 Jul 2026, 21:55 UTC Ubuntu 95% similarity 72.6

Article Content

Browse articles
ThreatCluster

Two vulnerabilities in AccountsService were discovered, allowing local attackers to execute arbitrary commands as administrators. The issues stem from improper handling of privileges and configuration files in the Ubuntu-specific SetLanguage patch. These vulnerabilities affect Ubuntu 14.04 LTS, 16.04 LTS, 18.04 LTS, and 20.04 LTS. The vulnerabilities are identified as CVE-2026-61897 and CVE-2026-61898. The first vulnerability allows privilege escalation due to mishandling of privilege dropping, while the second involves incorrect parsing of configuration files. Both vulnerabilities could be exploited by local attackers with access to the system. A patch has been released to address these vulnerabilities, and users are advised to update their systems. A reboot is required after applying the updates to ensure all changes take effect.

Key Points: • Two critical vulnerabilities in AccountsService allow local privilege escalation. • Affected Ubuntu versions include 14.04 LTS, 16.04 LTS, 18.04 LTS, and 20.04 LTS. • Users must update their systems and reboot to apply the necessary fixes.

ThreatCluster AI

Timeline

2026-07-21
USN-8580-2 released
Ubuntu released an update to fix vulnerabilities in AccountsService affecting multiple LTS versions.
Ubuntu
2026-07-21
USN-8580-1 published
Initial advisory detailing vulnerabilities in AccountsService was published, highlighting the risks of privilege escalation.
Ubuntu

Community

Browse all →