CVE-2026-12392
Received Received - Intake

Information Exposure in Canonical MAAS

Vulnerability report for CVE-2026-12392, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Canonical Ltd.

Description

An information exposure vulnerability in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows an unauthenticated attacker to retrieve the RPC secret in plaintext via the vendor data metadata endpoint. If a target machine was deployed with the 'register as rack' option enabled, an attacker who obtains or infers the machine's system ID can query the preseed/metadata server to leak the secret.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-03
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
canonical maas to 3.4.10 (exc)
canonical maas to 3.5.14 (exc)
canonical maas to 3.6.5 (exc)
canonical maas to 3.7.3 (exc)
canonical maas to 3.8.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an information exposure flaw in Canonical MAAS versions prior to 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0. An unauthenticated attacker can retrieve the RPC secret in plaintext via the vendor data metadata endpoint if a machine was deployed with the 'register as rack' option enabled. The attacker needs the machine's system ID to exploit this.

Detection Guidance

To detect this vulnerability, check if any machines in your MAAS deployment were configured with the 'install_rackd' parameter set to true. Inspect MAAS logs for attempts to deploy machines as rack controllers. Verify if the vendor data metadata endpoint is accessible and if RPC secrets are exposed in plaintext.

Impact Analysis

If exploited, an attacker can obtain the RPC secret, register additional rack controllers, leak BMC secrets, and perform further malicious activities within the MAAS environment. This could lead to unauthorized access and control over deployed machines.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by exposing sensitive RPC secrets if machines were deployed with the 'register as rack' option. Unauthorized access to these secrets may lead to unauthorized rack controller registration, BMC secret leaks, and further malicious activities, violating data protection and security requirements.

Mitigation Strategies

Upgrade MAAS to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, or 3.8.0 or later to disable the vulnerable 'install_rackd' feature. Ensure no machines are deployed with the 'register as rack' option enabled. Review and revoke any exposed RPC secrets.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12392. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart