PT-2026-51362 · Canonical · Adsys
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Canonical ADSys versions prior to v0.16.3
Description
An issue exists during Active Directory Certificate Services (AD CS) certificate auto-enrollment via the vendored Samba client script (internal/policies/certificate/python/vendor samba/gp/gp cert auto enroll ext.py). ADSys uses a plaintext HTTP connection instead of a secure HTTPS connection to request the CA certificate from the AD CS server through the
GetCACert function. An unauthenticated network attacker positioned between the managed Ubuntu host and the configured AD CS CA hostname can perform a Man-in-the-Middle (MITM) attack—a technique where an attacker intercepts communication between two parties. By intercepting the request, the attacker can provide a malicious Root CA certificate, which the system automatically accepts and registers into the local system trust store via update-ca-certificates. This leads to system-wide trust store poisoning, allowing TLS clients to accept rogue certificates for any domain and enabling the decryption and interception of subsequent TLS connections.Recommendations
Update to version v0.16.3.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adsys