CVE-2026-6369

An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to obtain a sensitive, root-level authentication token by sending an unauthenticated request to the livepatchd.sock Unix domain socket. This vulnerability is exploitable on systems where an administrator has already enabled the Livepatch client with a valid Ubuntu Pro subscription. This token allows an attacker to access Livepatch services using the victim's credentials, as well as potentially cause issues to the Livepatch server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:canonical:livepatch_client:*:*:*:*:*:*:*:*

History

05 Jun 2026, 18:36

Type Values Removed Values Added
References () https://discourse.ubuntu.com/t/security-notice-canonical-livepatch-client-snap-vulnerability/80662 - () https://discourse.ubuntu.com/t/security-notice-canonical-livepatch-client-snap-vulnerability/80662 - Vendor Advisory, Mitigation
First Time Canonical livepatch Client
Canonical
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:a:canonical:livepatch_client:*:*:*:*:*:*:*:*

20 Apr 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-20 14:16

Updated : 2026-06-05 18:36


NVD link : CVE-2026-6369

Mitre link : CVE-2026-6369

CVE.ORG link : CVE-2026-6369


JSON object : View

Products Affected

canonical

  • livepatch_client
CWE
CWE-306

Missing Authentication for Critical Function

CWE-732

Incorrect Permission Assignment for Critical Resource