Linuxsecurity
Critical Vulnerabilities in Cyborg API Affect Ubuntu Users
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Two critical vulnerabilities were discovered in the Cyborg API affecting Ubuntu 26.04 LTS and 25.10. The first vulnerability (CVE-2026-40214) allows authenticated users to delete Accelerator Requests (ARQs) linked to other projects, leading to cross-tenant denial of service. The second vulnerability (CVE-2026-40213) involves a permissive default policy that permits unauthorized actions, such as reprogramming FPGA bitstreams on compute nodes, for any request with a valid authentication token. These vulnerabilities were published on May 7, 2026, and users are advised to update their systems to mitigate the risks. Ubuntu Pro offers ten-year security coverage for affected packages. Immediate action is recommended to prevent potential exploitation.
Key Points: • Two critical vulnerabilities (CVE-2026-40213, CVE-2026-40214) impact Ubuntu 26.04 LTS and 25.10. • CVE-2026-40214 allows deletion of ARQs, risking cross-tenant denial of service. • CVE-2026-40213 permits unauthorized actions via a permissive default policy.