CVE-2026-61898
Publication date 21 July 2026
Last updated 7 August 2026
Ubuntu priority
Description
shell injection in SetLanguage helper scripts
Read the notes from the security team
Why is this CVE high priority?
Local privilege escalation issue
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| accountsservice | 26.04 LTS resolute |
Fixed 23.13.9-8ubuntu5.2
|
| 24.04 LTS noble |
Fixed 23.13.9-2ubuntu6.1
|
|
| 22.04 LTS jammy |
Fixed 22.07.5-2ubuntu1.6
|
|
| 20.04 LTS focal |
Fixed 0.6.55-0ubuntu12~20.04.7+esm1
|
|
| 18.04 LTS bionic |
Fixed 0.6.45-1ubuntu1.3+esm2
|
|
| 16.04 LTS xenial |
Fixed 0.6.40-2ubuntu11.6+esm2
|
|
| 14.04 LTS trusty |
Fixed 0.6.35-0ubuntu7.3+esm4
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu Pro 30-day free trialNotes
mdeslaur
This vulnerability is in the Ubuntu-specific 0009-language-tools.patch patch. The vulnerability does not affect the upstream accountsservice project.
References
Related Ubuntu Security Notices (USN)
- USN-8580-1
- AccountsService vulnerabilities
- 21 July 2026
- USN-8580-2
- AccountsService vulnerabilities
- 21 July 2026