Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-12249: Ubuntu ADSys uses less trusted source code

CVE-2026-12249 · published 4 days ago
Summary

The ADSys component provided by Ubuntu includes code from a source that is not fully trusted. This could allow a malicious change to be introduced into the software, potentially affecting systems that rely on it. Update to a version newer than v0.16.3-0.20250318112551-8b1939f96d38 or apply patches from the official Ubuntu repository to resolve the issue.

What to do
  • Update ubuntu github.com/ubuntu/adsys to version 0.16.3-0.20250318112551-8b1939f96d38.
  • Update github.com ubuntu to version 0.16.3-0.20250318112551-8b1939f96d38.
Affected software
Ecosystem VendorProductAffected versions
Go ubuntu github.com/ubuntu/adsys < 0.16.3-0.20250318112551-8b1939f96d38
Fix: upgrade to 0.16.3-0.20250318112551-8b1939f96d38
go github.com ubuntu < 0.16.3-0.20250318112551-8b1939f96d38
Fix: upgrade to 0.16.3-0.20250318112551-8b1939f96d38
Original advisory text
Canonical ADSys Uses a Less Trusted Source in github.com/ubuntu/adsys
Canonical ADSys Uses a Less Trusted Source in github.com/ubuntu/adsys.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: github.com/ubuntu/adsys before v0.16.3-0.20250318112551-8b1939f96d38.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-348Use of Less Trusted Source
Timeline
Published28 Sep 2026
Updated30 Sep 2026
First seen22 Jun 2026
Track software like this
Free during beta