PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-12392 Canonical CVE debrief

An information exposure vulnerability in Canonical MAAS allows an unauthenticated attacker to retrieve the RPC secret in plaintext via the vendor data metadata endpoint. This vulnerability requires attention from MAAS administrators and security teams to prevent potential exposure of sensitive information. Affected instances should be updated to a fixed version or have access to the preseed/metadata server restricted. Monitoring for exploitation attempts is also recommended. The vulnerability is caused by a lack of proper authentication and authorization in the vendor data metadata endpoint, which allows an attacker to access sensitive information without proper credentials.

Vendor
Canonical
Product
MAAS
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-02
Original CVE updated
2026-10-03
Advisory published
2026-10-02
Advisory updated
2026-10-03

Who should care

MAAS administrators, security teams, and IT professionals responsible for deploying and managing MAAS instances should be aware of this vulnerability and take steps to mitigate it. This includes reviewing and updating MAAS instances to fixed versions, restricting access to the preseed/metadata server, and monitoring for potential exploitation attempts. Additionally, security teams should review compensating controls for exposed systems and track exceptions

Why it matters

This vulnerability requires attention from MAAS administrators and security teams to prevent potential exposure of sensitive information. Affected instances should be updated to a fixed version or have access to the preseed/metadata server restricted. Monitoring for exploitation attempts is also recommended.

  • Potential exposure of sensitive information
  • Need for immediate version updates or access restrictions
  • Monitoring for exploitation attempts

Technical summary

The vulnerability allows an unauthenticated attacker to retrieve the RPC secret in plaintext via the vendor data metadata endpoint in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0. The vulnerability is caused by a lack of proper authentication and authorization in the vendor data metadata endpoint, which allows an attacker to access sensitive information without proper credentials. The affected product, Canonical MAAS, is a popular tool for managing and deploying servers. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM.

Defensive priority

Medium priority for MAAS administrators and security teams

Recommended defensive actions

  • Review and update MAAS instances to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, or 3.8.0
  • Restrict access to the preseed/metadata server
  • Monitor for potential exploitation attempts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but additional information is limited. The vulnerability was reported by a security researcher and is being tracked by the CVE Program. The affected product, Canonical MAAS, is a popular tool for managing and deploying servers. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. The CVE record and NVD entry provide additional information on the vulnerability, including affected versions and potential mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-12392 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-12392

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-12392 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12392

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.