A vulnerability, which was classified as very critical, has been found in Canonical ubuntu-pro-client. This affects the function str.format of the file /etc/apt/sources.list.d/ubuntu-.list of the component APT Source File Generation. This manipulation of the argument directives.aptURL/suites[]/additionalPackages[] causes improper input validation.

This vulnerability appears as CVE-2026-11386. The attack may be initiated remotely. There is no available exploit.