CVE-2026-6369: Exposed Session Token in canonical-livepatch client snap
An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to obtain a sensitive, root-level authentication token by sending an unauthenticated request to the livepatchd.sock Unix domain socket. This vulnerability is exploitable on systems where an administrator has already enabled the Livepatch client with a valid Ubuntu Pro subscription. This token allows an attacker to access Livepatch services using the victim's credentials, as well as potentially cause issues to the Livepatch server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
canonical-livepatch snap clientto a version that resolves this vulnerability.Fixed in 10.15.0 - Compensating control
Restrict local access to the livepatchd.sock Unix domain socket so that unprivileged local users cannot send requests to it (e.g., enforce appropriate filesystem/Unix socket permissions and/or isolate the socket from untrusted users).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6369?
CVE-2026-6369 has been classified as a medium severity vulnerability due to its potential impact on local user access.
How do I fix CVE-2026-6369?
To remediate CVE-2026-6369, update the canonical-livepatch snap client to version 10.15.0 or later.
What type of vulnerability is CVE-2026-6369?
CVE-2026-6369 is an improper access control vulnerability that exposes sensitive session information.
Who is affected by CVE-2026-6369?
Any local unprivileged user with access to the affected canonical-livepatch snap client prior to version 10.15.0 is at risk.
What can an attacker do with CVE-2026-6369?
An attacker can potentially obtain a sensitive, root-level authentication token by exploiting CVE-2026-6369.