CVE-2026-61898: accountsservice: shell injection via attacker-controlled ~/.pam_environment in Ubuntu language helper scripts
Last updated 2 September 2026
Other sources
The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pamenvironment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject a sed 'e' flag and arbitrary shell commands that execute with the privileges of the AccountsService helper process (real UID 0) via the SetLanguage D-Bus method.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/accountsserviceto a version that resolves this vulnerability.Fixed in 22.08.8-6Fixed in 23.13.9-7Fixed in 23.13.9-8 - Upgrade
Upgrade
accountsserviceto a version that resolves this vulnerability.Fixed in 23.13.9-8ubuntu7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61898?
CVE-2026-61898 has a risk rating of 2, indicating a low severity level.
What is the nature of the CVE-2026-61898 vulnerability?
CVE-2026-61898 is likely incorrectly documented and lacks a clear description of the vulnerability.
How can I confirm the existence of CVE-2026-61898 in my system?
To confirm CVE-2026-61898, you should consult your software documentation and security advisories for any mentions or alerts.
What should I do if I am affected by CVE-2026-61898?
If you suspect your system is affected by CVE-2026-61898, you should remain vigilant and await further information or official guidance.
Is there a known fix for CVE-2026-61898?
Currently, there is no known fix for CVE-2026-61898 due to the lack of detailed information regarding the vulnerability.