An information exposure vulnerability in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows an unauthenticated attacker to retrieve the RPC secret in plaintext via the vendor data metadata endpoint. If a target machine was deployed with the 'register as rack' option enabled, an attacker who obtains or infers the machine's system ID can query the preseed/metadata server to leak the secret.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 02 Oct 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 |
Fri, 02 Oct 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An information exposure vulnerability in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows an unauthenticated attacker to retrieve the RPC secret in plaintext via the vendor data metadata endpoint. If a target machine was deployed with the 'register as rack' option enabled, an attacker who obtains or infers the machine's system ID can query the preseed/metadata server to leak the secret. | |
| Title | RPC secret disclosure via vendor data endpoint in Canonical MAAS | |
| First Time appeared |
Canonical
Canonical maas |
|
| CPEs | cpe:2.3:a:canonical:maas:*:*:linux:*:*:*:*:* | |
| Vendors & Products |
Canonical
Canonical maas |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-10-02T19:24:09.110Z
Reserved: 2026-06-16T12:16:09.502Z
Link: CVE-2026-12392
No data.
Status : Received
Published: 2026-10-02T20:17:01.817
Modified: 2026-10-02T20:17:01.817
Link: CVE-2026-12392
No data.
OpenCVE Enrichment
Updated: 2026-10-02T20:30:16Z
Weaknesses