PatchSiren cyber security CVE debrief
CVE-2026-12392 Canonical CVE debrief
An information exposure vulnerability in Canonical MAAS allows an unauthenticated attacker to retrieve the RPC secret in plaintext via the vendor data metadata endpoint. This vulnerability requires attention from MAAS administrators and security teams to prevent potential exposure of sensitive information. Affected instances should be updated to a fixed version or have access to the preseed/metadata server restricted. Monitoring for exploitation attempts is also recommended. The vulnerability is caused by a lack of proper authentication and authorization in the vendor data metadata endpoint, which allows an attacker to access sensitive information without proper credentials.
- Vendor
- Canonical
- Product
- MAAS
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-02
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-02
- Advisory updated
- 2026-10-03
Who should care
MAAS administrators, security teams, and IT professionals responsible for deploying and managing MAAS instances should be aware of this vulnerability and take steps to mitigate it. This includes reviewing and updating MAAS instances to fixed versions, restricting access to the preseed/metadata server, and monitoring for potential exploitation attempts. Additionally, security teams should review compensating controls for exposed systems and track exceptions
Why it matters
This vulnerability requires attention from MAAS administrators and security teams to prevent potential exposure of sensitive information. Affected instances should be updated to a fixed version or have access to the preseed/metadata server restricted. Monitoring for exploitation attempts is also recommended.
- Potential exposure of sensitive information
- Need for immediate version updates or access restrictions
- Monitoring for exploitation attempts
Technical summary
The vulnerability allows an unauthenticated attacker to retrieve the RPC secret in plaintext via the vendor data metadata endpoint in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0. The vulnerability is caused by a lack of proper authentication and authorization in the vendor data metadata endpoint, which allows an attacker to access sensitive information without proper credentials. The affected product, Canonical MAAS, is a popular tool for managing and deploying servers. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM.
Defensive priority
Medium priority for MAAS administrators and security teams
Recommended defensive actions
- Review and update MAAS instances to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, or 3.8.0
- Restrict access to the preseed/metadata server
- Monitor for potential exploitation attempts
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but additional information is limited. The vulnerability was reported by a security researcher and is being tracked by the CVE Program. The affected product, Canonical MAAS, is a popular tool for managing and deploying servers. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. The CVE record and NVD entry provide additional information on the vulnerability, including affected versions and potential mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-12392 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-12392
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-12392 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12392
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://bugs.launchpad.net/maas/+bug/2153942
-
Source reference
Unverified legacy reference
URL: https://github.com/canonical/maas/commit/3864ef9dca54e36e3d34d18233b87666b8ee1dc8
-
Source reference
Unverified legacy reference
URL: https://github.com/canonical/maas/commit/65e89c05970f4514f9e6de043c2779017b43ad9d
-
Source reference
Unverified legacy reference
URL: https://github.com/canonical/maas/commit/8489979d64b0e7f124e7cef66d02b21263918f9b
-
Source reference
Unverified legacy reference
URL: https://github.com/canonical/maas/commit/a9486ad0cc90f4571142c1bea13f02d1361cb31e
-
Source reference
Unverified legacy reference
URL: https://github.com/canonical/maas/commit/ead659f70224538517c80478c3fd8c9e730aae79
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.