{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "extracted_events": [
              {
                "introduced": "3.4.0"
              },
              {
                "fixed": "3.4.10"
              },
              {
                "introduced": "3.5.0"
              },
              {
                "fixed": "3.5.14"
              },
              {
                "introduced": "3.6.0"
              },
              {
                "fixed": "3.6.5"
              },
              {
                "introduced": "3.7.0"
              },
              {
                "fixed": "3.7.3"
              }
            ],
            "source": [
              "AFFECTED_FIELD",
              "REFERENCES"
            ]
          },
          "events": [
            {
              "introduced": "1027c766413d7019ed1d3468c3ca18ac929b2475"
            },
            {
              "introduced": "c799a1080c32cd0e1eceb6f7844bd62f9986ce5d"
            },
            {
              "introduced": "561fe1a3ec5aadba77a6ae52da7a9e689cdc9f91"
            },
            {
              "introduced": "41ff7884805ba881ffc1bd517babde23a9f5b4cd"
            },
            {
              "fixed": "9d34090c1815652410b6e56b6b8d014fd8532334"
            },
            {
              "fixed": "21a535f5a890cbb6fcbea13e72f538871005f64d"
            },
            {
              "fixed": "46ca46d65354f84c6dc556f1f86ee4ecf82db1a9"
            },
            {
              "fixed": "9122eee6854592c9ca713c0e83725993911d368a"
            },
            {
              "fixed": "3864ef9dca54e36e3d34d18233b87666b8ee1dc8"
            },
            {
              "fixed": "65e89c05970f4514f9e6de043c2779017b43ad9d"
            },
            {
              "fixed": "8489979d64b0e7f124e7cef66d02b21263918f9b"
            },
            {
              "fixed": "a9486ad0cc90f4571142c1bea13f02d1361cb31e"
            },
            {
              "fixed": "ead659f70224538517c80478c3fd8c9e730aae79"
            }
          ],
          "repo": "https://github.com/canonical/maas",
          "type": "GIT"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "canonical",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12392.json",
    "unresolved_ranges": [
      {
        "extracted_events": [
          {
            "fixed": "3.8.0"
          }
        ],
        "source": "AFFECTED_FIELD"
      }
    ]
  },
  "details": "An information exposure vulnerability in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows an unauthenticated attacker to retrieve the RPC secret in plaintext via the vendor data metadata endpoint. If a target machine was deployed with the 'register as rack' option enabled, an attacker who obtains or infers the machine's system ID can query the preseed/metadata server to leak the secret.",
  "id": "CVE-2026-12392",
  "modified": "2026-10-06T02:30:38.361114416Z",
  "published": "2026-10-02T19:24:09.110Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12392.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12392"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.launchpad.net/maas/+bug/2153942"
    },
    {
      "type": "FIX",
      "url": "https://github.com/canonical/maas/commit/3864ef9dca54e36e3d34d18233b87666b8ee1dc8"
    },
    {
      "type": "FIX",
      "url": "https://github.com/canonical/maas/commit/65e89c05970f4514f9e6de043c2779017b43ad9d"
    },
    {
      "type": "FIX",
      "url": "https://github.com/canonical/maas/commit/8489979d64b0e7f124e7cef66d02b21263918f9b"
    },
    {
      "type": "FIX",
      "url": "https://github.com/canonical/maas/commit/a9486ad0cc90f4571142c1bea13f02d1361cb31e"
    },
    {
      "type": "FIX",
      "url": "https://github.com/canonical/maas/commit/ead659f70224538517c80478c3fd8c9e730aae79"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/canonical/maas"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "RPC secret disclosure via vendor data endpoint in Canonical MAAS"
}