Information Exposure Vulnerability in Canonical MAAS by Canonical
CVE-2026-12392

5.3MEDIUM

Key Information:

Vendor

Canonical

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-12392?

An information exposure vulnerability in Canonical MAAS versions before 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows unauthenticated attackers to access sensitive RPC secrets in plaintext. This occurs through the vendor data metadata endpoint when the 'register as rack' option is enabled on deployed machines. An attacker who manages to obtain or infer the system ID of a target machine can exploit this flaw to query the preseed/metadata server, thereby leaking the confidential RPC secret.

Affected Version(s)

MAAS Linux 3.4.0 < 3.4.10

MAAS Linux 3.5.0 < 3.5.14

MAAS Linux 3.6.0 < 3.6.5

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.