Vulnerability Description
An information exposure vulnerability in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows an unauthenticated attacker to retrieve the RPC secret in plaintext via the vendor data metadata endpoint. If a target machine was deployed with the 'register as rack' option enabled, an attacker who obtains or infers the machine's system ID can query the preseed/metadata server to leak the secret.
CVSS Score
MEDIUM
References
- https://bugs.launchpad.net/maas/+bug/2153942
- https://github.com/canonical/maas/commit/3864ef9dca54e36e3d34d18233b87666b8ee1dc
- https://github.com/canonical/maas/commit/65e89c05970f4514f9e6de043c2779017b43ad9
- https://github.com/canonical/maas/commit/8489979d64b0e7f124e7cef66d02b21263918f9
- https://github.com/canonical/maas/commit/a9486ad0cc90f4571142c1bea13f02d1361cb31
- https://github.com/canonical/maas/commit/ead659f70224538517c80478c3fd8c9e730aae7
FAQ
What is CVE-2026-12392?
CVE-2026-12392 is a vulnerability with a CVSS score of 5.3 (MEDIUM). An information exposure vulnerability in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows an unauthenticated attacker to retrieve the RPC secret in plaintext via the ven...
How severe is CVE-2026-12392?
CVE-2026-12392 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-12392?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.