This page lists publicly disclosed CVE vulnerabilities affecting canonical maas (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2025-7044 | An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user.update websocket request and inject the is_superuser property set to true. The server improperly validates this input, allowing the attacker to self-promote to an administrator role. This results in full administrative control over the MAAS deployment. | [email protected] | 7.7 | 0.23% | 2025-12-03 | 2026-06-17 |
| CVE-2013-1058 | maas-import-pxe-files in MAAS before 13.10 does not verify the integrity of downloaded files, which allows remote attackers to modify these files via a man-in-the-middle (MITM) attack. | [email protected] | 5.8 | 1.94% | 2013-11-23 | 2026-06-16 |
| CVE-2013-1057 | Untrusted search path vulnerability in maas-import-pxe-files in MAAS before 13.10 allows local users to execute arbitrary code via a Trojan horse import_pxe_files configuration file in the current working directory. | [email protected] | 4.4 | 0.59% | 2013-11-17 | 2026-06-16 |