CVE-2026-6369

An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to obtain a sensitive, root-level authentication token by sending an unauthenticated request to the livepatchd.sock Unix domain socket. This vulnerability is exploitable on systems where an administrator has already enabled the Livepatch client with a valid Ubuntu Pro subscription. This token allows an attacker to access Livepatch services using the victim's credentials, as well as potentially cause issues to the Livepatch server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:canonical:livepatch_client:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-20 14:16

Updated : 2026-06-17 11:00


NVD link : CVE-2026-6369

Mitre link : CVE-2026-6369

CVE.ORG link : CVE-2026-6369


JSON object : View

Products Affected

canonical

  • livepatch_client
CWE
CWE-306

Missing Authentication for Critical Function

CWE-732

Incorrect Permission Assignment for Critical Resource