CVE-2026-6369
EUVD-2026-2386220.04.2026, 14:16
An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to obtain a sensitive, root-level authentication token by sending an unauthenticated request to the livepatchd.sock Unix domain socket. This vulnerability is exploitable on systems where an administrator has already enabled the Livepatch client with a valid Ubuntu Pro subscription. This token allows an attacker to access Livepatch services using the victim's credentials, as well as potentially cause issues to the Livepatch server.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| canonical | livepatch_client | 𝑥 < 10.15.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration