Critical Vulnerabilities in Cyborg API Affect Ubuntu Users

Critical Vulnerabilities in Cyborg API Affect Ubuntu Users

First seen 9 Jun 2026, 20:20 UTC Ubuntulaunchpad.netLinuxsecurity 94% similarity 72.0

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities were discovered in the Cyborg API affecting Ubuntu 26.04 LTS and 25.10. The first vulnerability (CVE-2026-40214) allows authenticated users to delete Accelerator Requests (ARQs) linked to other projects, leading to cross-tenant denial of service. The second vulnerability (CVE-2026-40213) involves a permissive default policy that permits unauthorized actions, such as reprogramming FPGA bitstreams on compute nodes, for any request with a valid authentication token. These vulnerabilities were published on May 7, 2026, and users are advised to update their systems to mitigate the risks. Ubuntu Pro offers ten-year security coverage for affected packages. Immediate action is recommended to prevent potential exploitation.

Key Points: • Two critical vulnerabilities (CVE-2026-40213, CVE-2026-40214) impact Ubuntu 26.04 LTS and 25.10. • CVE-2026-40214 allows deletion of ARQs, risking cross-tenant denial of service. • CVE-2026-40213 permits unauthorized actions via a permissive default policy.

ThreatCluster AI

Timeline

2026-05-07
CVE-2026-40213 published
A permissive policy in Cyborg API allows unauthorized actions, affecting multiple endpoints.
Ubuntu
2026-05-07
CVE-2026-40214 published
Improper project ownership enforcement in Cyborg API enables deletion of ARQs across projects.
Linuxsecurity
2026-06-09
Security notice issued
Ubuntu released a security notice urging users to update their systems to mitigate vulnerabilities.
Ubuntu

Community

Browse all →

Tracked Entities in This Story