CVE-2026-102371 PUBLISHED

wsl-pro-service: Ubuntu Pro token exposed via process command-line arguments

Assigner: canonical
Reserved: 28.09.2026 Published: 29.09.2026 Updated: 29.09.2026

In wsl-pro-service before 0.1.19ubuntu3, the service component which runs as root inside each WSL instance attaches the instance to Ubuntu Pro by executing the pro client with the Ubuntu Pro token passed as a command-line argument (pro attach <token>). On systems where /proc is mounted without process-hiding mitigations (such as hidepid), which is the default in WSL, an unprivileged local user or process in the same WSL instance can read the token from /proc/<pid>/cmdline while the attach process is running. The leaked token could then be used to attach other machines to the victim's Ubuntu Pro subscription and gain unauthorized access to Ubuntu Pro services.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.7

Product Status

Vendor Canonical
Product Ubuntu Pro for WSL
Versions Default: unaffected
  • affected from 0.1.1 to 0.1.19ubuntu2 (excl.)
  • affected from 0.1.1 to 0.1.18~24.04.3 (excl.)
  • affected from 0.1.1 to 0.1.18~22.04.2 (excl.)
  • affected from 0.1.1 to 0.1.18~20.04.2 (excl.)

Credits

  • Darshan U reporter
  • Carlos Nihelton remediation developer

References

Problem Types

  • CWE-214 Invocation of process using visible sensitive information CWE

Impacts

  • CAPEC-639 Probe System Files