News

USN-8892-1: Ubuntu Pro for WSL Exposes the Activation Token

A bug in wsl-pro-service exposes the Ubuntu Pro token in command-line arguments. A fix is available for all supported releases.

UptimeMag editorial team · 7 October 2026 · 1 min read

USN-8892-1: Ubuntu Pro for WSL espone il token di attivazione

Canonical published advisory USN-8892-1 on 6 October 2026, fixing a flaw in the wsl-pro-service package, the service that manages Ubuntu Pro for WSL. It affects anyone running Ubuntu on Windows Subsystem for Linux with an active Pro subscription, a typical scenario for development and CI on Windows machines.\n\n## The problem\n\nAccording to the official Ubuntu advisory, the service exposed the attach token (the token used to bind the machine to the Ubuntu Pro subscription) in the command-line arguments at the moment of activation on a WSL instance. A token passed as a process argument is visible to other local users, for example via ps aux or equivalent tools on Windows/WSL.\n\nAn attacker with access to the same machine could therefore read the token and use it to gain unauthorised access to the Ubuntu Pro repositories, which on ESM Apps and ESM Infra contain packages with security patches reserved for subscribers. The vulnerability was discovered by Darshan U and is tracked as CVE-2026-102371.\n\n## Fixed versions\n\n| Ubuntu release | Codename | Fixed version |\n|---|---|---|\n| 26.04 LTS | resolute | wsl-pro-service 0.1.19ubuntu2.1 |\n| 24.04 LTS | noble | wsl-pro-service 0.1.1824.04.4 |\n| 22.04 LTS | jammy | wsl-pro-service 0.1.1822.04.3 |\n| 20.04 LTS | focal | wsl-pro-service 0.1.18~20.04.2+esm1 |\n\nFor 20.04 LTS, the fix is only available through Ubuntu Pro via ESM Apps. Canonical notes that a public fix without a subscription may arrive in future, but gives no date.\n\n## How to fix it\n\nOn systems with Ubuntu Pro for WSL, a standard package update is all that's needed:\n\n\nsudo apt update && sudo apt install --only-upgrade wsl-pro-service\n\n\nAnyone who has already activated a subscription with a vulnerable version should assess whether the token may have been exposed to other local accounts on the same machine and, if in doubt, regenerate it from the Ubuntu Pro dashboard. The full reference, with the original text of the advisory and a link to the CVE, is on the official page at ubuntu.com/security/notices/USN-8892-1.

Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.