CVE-2026-102371
Received Received - Intake

Ubuntu Pro Token Exposure in wsl-pro-service

Vulnerability report for CVE-2026-102371, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Canonical Ltd.

Description

In wsl-pro-service before 0.1.19ubuntu3, the service component which runs as root inside each WSL instance attaches the instance to Ubuntu Pro by executing the pro client with the Ubuntu Pro token passed as a command-line argument (pro attach <token>). On systems where /proc is mounted without process-hiding mitigations (such as hidepid), which is the default in WSL, an unprivileged local user or process in the same WSL instance can read the token from /proc/<pid>/cmdline while the attach process is running. The leaked token could then be used to attach other machines to the victim's Ubuntu Pro subscription and gain unauthorized access to Ubuntu Pro services.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ubuntu pro_service to 0.1.19ubuntu3 (exc)
canonical wsl-pro-service to 0.1.19ubuntu3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-214 A process is invoked with sensitive command-line arguments, environment variables, or other elements that can be seen by other processes on the operating system.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a flaw in the wsl-pro-service before version 0.1.19ubuntu3 where the Ubuntu Pro token is passed as a command-line argument to the pro client. On systems with /proc mounted without process-hiding mitigations, an unprivileged local user can read the token from /proc/<pid>/cmdline while the attach process runs. The leaked token could allow unauthorized attachment of other machines to the victim's Ubuntu Pro subscription.

Detection Guidance

Check if the wsl-pro-service version is before 0.1.19ubuntu3 by running: wsl-pro-service --version. If vulnerable, inspect /proc for processes running pro attach with tokens in cmdline. Look for unauthorized Ubuntu Pro attachments in your Ubuntu Pro dashboard.

Impact Analysis

If you use Ubuntu Pro for WSL on a system where /proc is not properly secured, an attacker with local access could steal your Pro token. This token could then be used to attach other machines to your subscription without permission, potentially consuming your subscription quota or gaining access to restricted Ubuntu Pro services.

Mitigation Strategies

Update wsl-pro-service to version 0.1.19ubuntu3 or later. Verify the update by checking the version again. Ensure no unauthorized Ubuntu Pro attachments exist in your account.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102371. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart