📦

maas

Vendor: canonical

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 1 Remote Access
Total CVEs 8 Total Indexed
Avg. EPSS 0.92% Exploit Prob.
Latest CVE CVE-2025-7044 Dec 03

Security Vulnerability Index

Page 1 / 1
7.7 CVSS

An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user.update websocket request and inject the is_superuser property set to true. The server improperly validates this input, allowing the attacker to self-promote to an administrator role. This results in full administrative control over the MAAS deployment.

EPSS: 0.24%
5.8 CVSS

maas-import-pxe-files in MAAS before 13.10 does not verify the integrity of downloaded files, which allows remote attackers to modify these files via a man-in-the-middle (MITM) attack.

EPSS: 1.94%
4.4 CVSS

Untrusted search path vulnerability in maas-import-pxe-files in MAAS before 13.10 allows local users to execute arbitrary code via a Trojan horse import_pxe_files configuration file in the current working directory.

EPSS: 0.59%