Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Carlos Nihelton

#48573of 57,591
5.7Total CVSS
Vulnerabilities · 1
PT-2026-102618
5.7
2026-09-29
Canonical · Wsl-Pro-Service · CVE-2026-102371
**Name of the Vulnerable Software and Affected Versions** wsl-pro-service versions prior to 0.1.19ubuntu3 **Description** A service component running as root within a WSL instance attaches the instance to Ubuntu Pro by executing the pro client and passing the Ubuntu Pro token as a command-line argument. On systems where `/proc` is mounted without process-hiding mitigations like `hidepid` (the default in WSL), an unprivileged local user or process can read the token from `/proc/<pid>/cmdline` during the attachment process. This leak allows an attacker to use the token to attach other machines to the victim's subscription and gain unauthorized access to Ubuntu Pro services and repositories. **Recommendations** Update wsl-pro-service to version 0.1.19ubuntu3 or later.