CVE-2026-6369 Details
Description
An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to obtain a sensitive, root-level authentication token by sending an unauthenticated request to the livepatchd.sock Unix domain socket. This vulnerability is exploitable on systems where an administrator has already enabled the Livepatch client with a valid Ubuntu Pro subscription. This token allows an attacker to access Livepatch services using the victim's credentials, as well as potentially cause issues to the Livepatch server.
An improper access control vulnerability exists in the canonical-livepatch snap client versions prior to 10.15.0. This vulnerability allows local unprivileged users to obtain a sensitive root-level authentication token by sending an unauthenticated request to the livepatchd.sock Unix domain socket. The issue arises on systems where the Livepatch client has been enabled with a valid Ubuntu Pro subscription, allowing the token to be used to access Livepatch services with the victim's credentials and potentially disrupt the Livepatch server.
To address this vulnerability, update the canonical-livepatch snap to version 10.15.0 or later. If the snap is installed from the latest/stable channel and automatic refreshes are not on hold, it will be updated automatically. To manually update, use the command 'sudo snap refresh canonical-livepatch --channel latest/stable'. After updating, verify the version with 'canonical-livepatch --version'.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://discourse.ubuntu.com/t/security-notice-canonical-livepatch-client-snap-vulnerability/80662 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
| CWE-732 | Incorrect Permission Assignment for Critical Resource | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| canonical livepatch client | < 10.15.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 5, 2026 | Initial Analysis | [email protected] |
| Apr 20, 2026 | New CVE Received | [email protected] |