# USN-8857-1: KCoreAddons vulnerability

Publisher-attributed story with a reviewed brief or permitted publisher paragraph. The original publisher is responsible for the linked reporting.

- Publisher: Ubuntu Security
- Category: Vulnerabilities
- Original publication time: 2026-10-01T10:48:57Z
- First observed by NexusTechWire: 2026-10-01T15:54:36Z
- Original source: https://ubuntu.com/security/notices/USN-8857-1
- NexusTechWire record: https://nexustechwire.com/news/news-dd90cbda44a813af6bd8

## The brief

A shell-quoting flaw in KCoreAddons could let hostile input become commands in applications that rely on the affected function. Ubuntu's advisory identifies KShell::quoteArgs and provides an updated package for 26.04 LTS. The described risk depends on an application passing attacker-controlled input through that method, rather than proving every installed application is exploitable.

AI-assisted NexusTechWire summary, checked against the linked source on 2026-10-01T19:12:54Z. Not independent reporting.

Read the full original: [Ubuntu Security](https://ubuntu.com/security/notices/USN-8857-1)

This record does not reproduce the complete article or represent independent confirmation of every source claim.
