CVE-2026-6369
Last modified
CVE-2026-6369 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to obtain a sensitive, root-level authentication token by sending an unauthenticated request to the livepatchd.sock Unix domain socket. This vulnerability is exploitable on systems where an administrator has already enabled the Livepatch client with a valid Ubuntu Pro subscription. This token allows an attacker to access Livepatch services using the victim's credentials, as well as potentially cause issues to the Livepatch server.. EPSS estimates a 0.12% chance of exploitation in the next 30 days.
Description
An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to obtain a sensitive, root-level authentication token by sending an unauthenticated request to the livepatchd.sock Unix domain socket. This vulnerability is exploitable on systems where an administrator has already enabled the Livepatch client with a valid Ubuntu Pro subscription. This token allows an attacker to access Livepatch services using the victim's credentials, as well as potentially cause issues to the Livepatch server.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Livepatch Client | < 10.15.0 |
References
- https://discourse.ubuntu.com/t/security-notice-canonical-livepatch-client-snap-vulnerability/80662Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-6369?
How severe is CVE-2026-6369?
How do I fix CVE-2026-6369?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-63671MDC is a tool to take regular Markdown and write documents i…8.1
- CVE-2026-6368Calling wordexp with WRDE_APPEND in the GNU C Library versio…2.1
- CVE-2026-63683Joomla Extension - regularlabs.com - Client IP spoofing vuln…7.5
- CVE-2026-63684Joomla Extension - regularlabs.com - Inconsistent CSRF token…8.8
- CVE-2026-63685Joomla Extension - regularlabs.com - Authorization bypass in…8.8
- CVE-2026-63687Apache CXF's JwtRequestCodeFilter copies all claims from a s…9.1
- CVE-2026-63693Dell Client BIOS contains an Improper Link Resolution Before…6.6
- CVE-2026-63694Dell SmartFabric OS10 Software, versions prior to 10.5.6.14,…5
- CVE-2026-63695Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, …9.8
- CVE-2026-63696Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, …9.1
- CVE-2026-6370Improper Neutralization of Input During Web Page Generation …5.9
- CVE-2026-63700Dell Wyse Management Suite (WMS), versions prior to 2605.0.2…7.8
Are you affected by CVE-2026-6369?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
