Skip to content
Critical Vulnerabilities in Cyborg API Affect Ubuntu Users

Critical Vulnerabilities in Cyborg API Affect Ubuntu Users

First seen 9 Jun 2026, 20:20 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 10, 2026 at 20:17 UTC

Two critical vulnerabilities were discovered in the Cyborg API affecting Ubuntu 26.04 LTS and 25.10. The first vulnerability (CVE-2026-40214) allows authenticated users to delete Accelerator Requests (ARQs) linked to other projects, leading to cross-tenant denial of service. The second vulnerability (CVE-2026-40213) involves a permissive default policy that permits unauthorized actions, such as reprogramming FPGA bitstreams on compute nodes, for any request with a valid authentication token. These vulnerabilities were published on May 7, 2026, and users are advised to update their systems to mitigate the risks. Ubuntu Pro offers ten-year security coverage for affected packages. Immediate action is recommended to prevent potential exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 102d ago How this analysis works

Timeline

2026-05-07
CVE-2026-40213 published
A permissive policy in Cyborg API allows unauthorized actions, affecting multiple endpoints.
Ubuntu
2026-05-07
CVE-2026-40214 published
Improper project ownership enforcement in Cyborg API enables deletion of ARQs across projects.
Linuxsecurity
2026-06-09
Security notice issued
Ubuntu released a security notice urging users to update their systems to mitigate vulnerabilities.
Ubuntu

More articles in this cluster (4)

Following this threat?

Track Ubuntu and CVE-2026-40213 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed