Transmission could allow unintended actions if a user visited a malicious
website.
Software Description:
- transmission: lightweight BitTorrent client
Details:
It was discovered that Transmission had a clickjacking weakness in the
browser-facing WebUI and RPC response paths. An attacker could possibly use
this issue to trick users into performing unintended actions.
The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS transmission 4.1.1+dfsg-1ubuntu1.1 transmission-daemon 4.1.1+dfsg-1ubuntu1.1 Ubuntu 25.10 transmission 4.1.0~beta2+dfsg-3ubuntu1.1 transmission-daemon 4.1.0~beta2+dfsg-3ubuntu1.1 Ubuntu 24.04 LTS transmission 4.0.5-1ubuntu0.1 transmission-daemon 4.0.5-1ubuntu0.1 Ubuntu 22.04 LTS transmission 3.00-2ubuntu2.2 transmission-daemon 3.00-2ubuntu2.2 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-8404-1
CVE-2026-38978
Get the latest Linux and open source security news straight to your inbox.