Ubuntu Security Notices USN-8580-1 USN-8580-1: AccountsService vulnerabilities Publication date 21 July 2026 Overview AccountsService could be made to run programs as an administrator if it opened a specially crafted file. Releases 26.04 LTS 24.04 LTS 22.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Packages accountsservice - query and manipulate user account information Details It was discovered that the Ubuntu-specific SetLanguage patch to AccountsService incorrectly handled dropping privileges. A local attacker could use this issue to execute arbitrary commands as an administrator. ( CVE-2026-61897 ) It was discovered that the Ubuntu-specific SetLanguage helpers for AccountsService incorrectly handled parsing configuration files. A local attacker could use this issue to execute arbitrary commands. ( CVE-2026-61898 ) It was discovered that the Ubuntu-specific SetLanguage patch to AccountsService incorrectly handled dropping privileges. A local attacker could use this issue to execute arbitrary commands as an administrator. ( CVE-2026-61897 ) It was discovered that the Ubuntu-specific SetLanguage helpers for AccountsService incorrectly handled parsing configuration files. A local attacker could use this issue to execute arbitrary commands. ( CVE-2026-61898 ) Update instructions After a standard system update you need to reboot your computer to make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 26.04 LTS resolute accountsservice – 23.13.9-8ubuntu5.2 libaccountsservice0 – 23.13.9-8ubuntu5.2 24.04 LTS noble accountsservice – 23.13.9-2ubuntu6.1 libaccountsservice0 – 23.13.9-2ubuntu6.1 22.04 LTS jammy accountsservice – 22.07.5-2ubuntu1.6 libaccountsservice0 – 22.07.5-2ubuntu1.6 Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-61898 CVE-2026-61897 CVE-2026-61898 CVE-2026-61897
Two vulnerabilities (CVE-2026-61897 and CVE-2026-61898) in Ubuntu's patched AccountsService allow local attackers to execute arbitrary commands, with CVE-2026-61897 enabling privilege escalation to administrator. The flaws are in the Ubuntu-specific SetLanguage patch and its helpers, which mishandle privilege dropping and configuration file parsing. Affected Ubuntu LTS releases 22.04, 24.04, and 26.04 require updates to specific package versions (e.g., accountsservice 23.13.9-8ubuntu5.2 for 26.04) followed by a system reboot.