Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-6369

Опубликовано: 20 апр. 2026
Источник: nvd
CVSS3: 5.5
EPSS Низкий

Описание

An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to obtain a sensitive, root-level authentication token by sending an unauthenticated request to the livepatchd.sock Unix domain socket. This vulnerability is exploitable on systems where an administrator has already enabled the Livepatch client with a valid Ubuntu Pro subscription. This token allows an attacker to access Livepatch services using the victim's credentials, as well as potentially cause issues to the Livepatch server.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:canonical:livepatch_client:*:*:*:*:*:*:*:*
Версия до 10.15.0 (исключая)

EPSS

Процентиль: 2%
0.00121
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 5.5
github
4 месяца назад

An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to obtain a sensitive, root-level authentication token by sending an unauthenticated request to the livepatchd.sock Unix domain socket. This vulnerability is exploitable on systems where an administrator has already enabled the Livepatch client with a valid Ubuntu Pro subscription. This token allows an attacker to access Livepatch services using the victim's credentials, as well as potentially cause issues to the Livepatch server.

EPSS

Процентиль: 2%
0.00121
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-306