CVE-2026-6369 is an improper access control vulnerability affecting the canonical-livepatch snap client prior to version 10.15.0. This flaw allows unprivileged local users to obtain root-level authentication tokens through unauthenticated requests to the livepatchd.sock Unix domain socket on systems with Livepatch enabled and a valid Ubuntu Pro subscription. The vulnerability is relevant to Ubuntu systems where Livepatch has been administratively deployed. An attacker exploiting this vulnerability could impersonate the victim, access Livepatch services using their credentials, and potentially disrupt or manipulate the Livepatch server. The attack vector is local and does not require authentication or user interaction, making it accessible to any unprivileged user on an affected system. Current threat assessment indicates no active exploitation in the wild, as the vulnerability is not included in CISA's Known Exploited Vulnerabilities catalog and maintains an inactive status on threat tracking lists. The FAUCET risk score of 42.0/100 suggests moderate concern requiring patching through upgrade to version 10.15.0 or later, though the extremely low EPSS score of 0.00017 indicates limited prevalence in exploit activity across the broader threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.15.0CPE matchmatch criteria | cpe:2.3:a:canonical:livepatch_client:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.