CVE-2026-61897: accountsservice: incomplete privilege drop when running Ubuntu-specific language helper scripts

Published Aug 20, 2026
·
Updated

An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to root, enabling local privilege escalation.

Affected Software

2 affected componentsFixes available
accountsservice<23.13.9-8ubuntu7
debian/accountsservice
22.08.8-623.13.9-723.13.9-8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/accountsservice to a version that resolves this vulnerability.

    Fixed in 22.08.8-6Fixed in 23.13.9-7Fixed in 23.13.9-8
  2. Upgrade

    Upgrade accountsservice to a version that resolves this vulnerability.

    Fixed in 23.13.9-8ubuntu7
  3. Compensating control

    Ensure helper scripts run with non-root privileges by preventing inheritance of ruid=0 (root) so the real UID cannot remain 0 when launching language helper scripts.

Event History

Aug 20, 2026
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Aug 21, 2026
Data Sourced
via Launchpad·02:47 PM
Description
Sep 3, 2026
Data Sourced
via Ubuntu·05:46 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·05:47 PM
DescriptionAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-61897?

CVE-2026-61897 has been assigned a risk level of 2, indicating a low severity vulnerability.

2

What systems are affected by CVE-2026-61897?

The details on affected systems for CVE-2026-61897 are currently unspecified due to the entry's likely erroneous nature.

3

What potential impact does CVE-2026-61897 have on security?

As CVE-2026-61897 is likely erroneous, its potential impact on security is currently unclear.

4

How can I stay updated on CVE-2026-61897?

You can monitor updates about CVE-2026-61897 through official CVE databases and security advisories.

5

How do I mitigate CVE-2026-61897?

Due to the likely erroneous nature of CVE-2026-61897, specific mitigation steps are not currently provided.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203