Token Leakage Vulnerability in Ubuntu Pro for WSL by Canonical
CVE-2026-102371

5.7MEDIUM

Key Information:

Vendor

Canonical

Vendor
CVE Published:
29 September 2026

What is CVE-2026-102371?

A vulnerability exists in the Ubuntu Pro for WSL service that allows an unprivileged local user or process to leak the subscription token while the pro client is attaching the instance. This occurs due to the default process transparency settings in WSL, enabling access to the command-line arguments via /proc//cmdline. Consequently, an attacker could misuse the leaked token to connect other machines to the victim’s Ubuntu Pro subscription, gaining unauthorized access to its services.

Affected Version(s)

Ubuntu Pro for WSL Linux 0.1.1 < 0.1.19ubuntu2

Ubuntu Pro for WSL Linux 0.1.1 < 0.1.18~24.04.3

Ubuntu Pro for WSL Linux 0.1.1 < 0.1.18~22.04.2

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Darshan U
Carlos Nihelton
.