High severity7.8NVD Advisory· Published Aug 20, 2026· Updated Aug 28, 2026
CVE-2026-61897
CVE-2026-61897
Description
An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to root, enabling local privilege escalation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <23.13.9-8ubuntu7
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.