PT-2026-51362 · Canonical · Adsys

·

CVE-2026-12249

·

Published

2026-06-22

·

Updated

2026-06-23

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Canonical ADSys versions prior to v0.16.3
Description An issue exists during Active Directory Certificate Services (AD CS) certificate auto-enrollment via the vendored Samba client script (internal/policies/certificate/python/vendor samba/gp/gp cert auto enroll ext.py). ADSys uses a plaintext HTTP connection instead of a secure HTTPS connection to request the CA certificate from the AD CS server through the GetCACert function. An unauthenticated network attacker positioned between the managed Ubuntu host and the configured AD CS CA hostname can perform a Man-in-the-Middle (MITM) attack—a technique where an attacker intercepts communication between two parties. By intercepting the request, the attacker can provide a malicious Root CA certificate, which the system automatically accepts and registers into the local system trust store via update-ca-certificates. This leads to system-wide trust store poisoning, allowing TLS clients to accept rogue certificates for any domain and enabling the decryption and interception of subsequent TLS connections.
Recommendations Update to version v0.16.3.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12249

Affected Products

Adsys