VDB

CVE-2026-6970

CVE-2026-6970 PUBLISHED CVSS 7.300000190734863 HIGH

authd prior to version 0.6.4 contains a logic error in primary group ID assignment that can lead to local privilege escalation. When a user's primary group ID (GID) differs from their UID, either because the account was created with authd prior to version 0.5.4 or because the primary group was manually changed via the `authctl group set-gid` command, and the user's identity provider record is updated, authd incorrectly resets the user's primary group ID to their UID upon next login. This causes newly created files and directories to be owned by the wrong group, causing denial of service issues, and potentially granting unintended access to other local users and allowing local privilege escalation.

EPSS 0.11% · 1.5th percentile

Risk Scores

CVSS 4.0
7.300000190734863
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.11%
1.5th percentile

Affected Products

VendorProductVersions
Canonicalauthd0.6.0, 0.6.1

Timeline

  • Apr 27, 2026 CVE Published
  • Apr 27, 2026 CVE Updated
  • Apr 28, 2026 EPSS Score
  • May 16, 2026 Security Advisory
  • May 18, 2026 EPSS Score
  • May 19, 2026 EPSS Score
  • May 20, 2026 EPSS Score
  • May 21, 2026 EPSS Score
  • May 22, 2026 EPSS Score
  • May 23, 2026 EPSS Score
  • May 24, 2026 EPSS Score
  • May 25, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›