CVE-2026-12392 | Canonical Maas up to 3.7.x Vendor Data Metadata Endpoint missing encryption
A vulnerability classified as problematic was found in Canonical Maas up to 3.4.9/3.5.13/3.6.4/3.7.2/3.7.x. The affected element is an unknown function of the component Vendor Data Metadata Endpoint. Such manipulation leads to missing encryption of sensitive data.
This vulnerability is referenced as CVE-2026-12392. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More