authd prior to version 0.6.4 contains a logic error in primary group ID assignment that can lead to local privilege escalation. When a user's primary group ID (GID) differs from their UID, either because the account was created with authd prior to version 0.5.4 or because the primary group was manually changed via the authctl group set-gid command, and the user's identity provider record is updated, authd incorrectly resets the user's primary group ID to their UID upon next login. This causes newly created files and directories to be owned by the wrong group, causing denial of service issues, and potentially granting unintended access to other local users and allowing local privilege escalation.
CVE-2026-6970
This high-severity CVE scores 7.3 under NVD CVSS v3. EPSS exploit probability: 0.0%, top 96% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- High severity, but no confirmed exploitation yet
A fix is available — apply it.
- CVSS v3
- 7.3
- EG Score
- 7.3(medium)
- EPSS
- 1.5%
- KEV
- Not listed
Published
April 27, 2026
Last Modified
April 27, 2026
Advisory Details (2)
Auto-updated Jun 11, 2026Primary group ID incorrectly set to value of UID · Advisory · canonical/authd · GitHub
https://github.com/canonical/authd/security/advisories/GHSA-fg3j-5w9g-hmg7commit 154b428305cb (canonical/authd)
Fix landed in canonical/authd commit 154b428305cb — awaiting tagged release
https://github.com/canonical/authd/commit/154b428305cb1a7a19c897626fefd09d6dde8b9fPatch Availability(1)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| ubuntu | authd (0.6.1ubuntu0.1) @ resolute | 2026-06-14 | ubuntu |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(1 across 1 ecosystem)
Go(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| github.com/canonical/authd | — | 0.6.4 | — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
All Vendor Advisories
(1)
Every vendor that published an advisory referencing this CVE — pulled from our cve_vendor_advisories aggregation. Click any row for the vendor's original advisory page.
Data Freshness Timeline
(refreshed 9× in last 7d / 34× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 103 total refreshes for this CVE.
- 2026-07-22 14:08 UTCEPSS rescore
- 2026-07-22 14:08 UTCEPSS rescore
- 2026-07-21 15:25 UTCEPSS rescore
- 2026-07-21 15:25 UTCEPSS rescore
- 2026-07-20 17:08 UTCEPSS rescore
- 2026-07-20 13:04 UTCOSV refresh
- 2026-07-19 14:31 UTCEPSS rescore
- 2026-07-18 10:04 UTCEPSS rescore
- 2026-07-16 17:03 UTCEPSS rescore
- 2026-07-15 16:57 UTCEPSS rescore
- 2026-07-15 02:00 UTCEPSS rescore
- 2026-07-13 22:31 UTCEPSS rescore
- 2026-07-12 05:46 UTCEPSS rescore
- 2026-07-11 08:27 UTCEPSS rescore
- 2026-07-11 08:27 UTCEPSS rescore
- 2026-07-09 19:10 UTCEPSS rescore
- 2026-07-09 19:10 UTCEPSS rescore
- 2026-07-08 15:16 UTCEPSS rescore
- 2026-07-08 15:16 UTCEPSS rescore
- 2026-07-07 13:46 UTCEPSS rescore
- 2026-07-07 13:46 UTCEPSS rescore
- 2026-07-06 02:23 UTCEPSS rescore
- 2026-07-06 02:23 UTCEPSS rescore
- 2026-07-05 02:31 UTCEPSS rescore
- 2026-07-05 02:30 UTCEPSS rescore
Show 75 moreShow fewer
- 2026-07-04 06:31 UTCEPSS rescore
- 2026-07-04 06:31 UTCEPSS rescore
- 2026-07-01 15:07 UTCEPSS rescore
- 2026-06-30 23:22 UTCEPSS rescore
- 2026-06-29 14:06 UTCEPSS rescore
- 2026-06-28 14:07 UTCEPSS rescore
- 2026-06-27 03:08 UTCEPSS rescore
- 2026-06-24 14:05 UTCEPSS rescore
- 2026-06-23 21:33 UTCEPSS rescore
- 2026-06-21 14:56 UTCEPSS rescore
- 2026-06-21 14:56 UTCEPSS rescore
- 2026-06-21 01:59 UTCEPSS rescore
- 2026-06-21 01:59 UTCEPSS rescore
- 2026-06-19 19:26 UTCEPSS rescore
- 2026-06-19 19:26 UTCEPSS rescore
- 2026-06-18 17:52 UTCEPSS rescore
- 2026-06-18 17:52 UTCEPSS rescore
- 2026-06-17 17:53 UTCEPSS rescore
- 2026-06-16 17:53 UTCEPSS rescore
- 2026-06-15 17:49 UTCEPSS rescore
- 2026-06-15 17:49 UTCEPSS rescore
- 2026-06-14 23:18 UTCEPSS rescore
- 2026-06-14 22:46 UTCVendor advisory
- 2026-06-14 11:03 UTCVendor advisory
- 2026-06-13 23:00 UTCEPSS rescore
- 2026-06-12 23:12 UTCEPSS rescore
- 2026-06-12 23:12 UTCEPSS rescore
- 2026-06-12 10:42 UTCVendor advisory
- 2026-06-11 21:34 UTCVendor advisory
- 2026-06-11 14:00 UTCEPSS rescore
- 2026-06-11 10:08 UTCVendor advisory
- 2026-06-10 22:36 UTCVendor advisory
- 2026-06-10 22:19 UTCEPSS rescore
- 2026-06-10 13:22 UTCEPSS rescore
- 2026-06-10 11:07 UTCVendor advisory
- 2026-06-09 23:40 UTCVendor advisory
- 2026-06-09 11:38 UTCVendor advisory
- 2026-06-09 00:11 UTCVendor advisory
- 2026-06-08 14:17 UTCEPSS rescore
- 2026-06-08 07:03 UTCVendor advisory
- 2026-06-07 19:36 UTCVendor advisory
- 2026-06-07 15:25 UTCEPSS rescore
- 2026-06-07 08:10 UTCVendor advisory
- 2026-06-06 20:44 UTCVendor advisory
- 2026-06-06 13:47 UTCEPSS rescore
- 2026-06-06 09:16 UTCVendor advisory
- 2026-06-05 22:47 UTCEPSS rescore
- 2026-06-05 21:48 UTCVendor advisory
- 2026-06-05 10:21 UTCVendor advisory
- 2026-06-05 06:10 UTCEPSS rescore
- 2026-06-04 22:03 UTCVendor advisory
- 2026-06-04 13:12 UTCEPSS rescore
- 2026-06-04 10:28 UTCVendor advisory
- 2026-06-03 22:19 UTCVendor advisory
- 2026-06-03 10:36 UTCVendor advisory
- 2026-06-02 22:39 UTCVendor advisory
- 2026-06-02 20:13 UTCEPSS rescore
- 2026-06-02 11:12 UTCVendor advisory
- 2026-06-01 23:07 UTCVendor advisory
- 2026-06-01 13:52 UTCEPSS rescore
- 2026-06-01 11:39 UTCVendor advisory
- 2026-05-31 22:30 UTCEPSS rescore
- 2026-05-31 22:30 UTCEPSS rescore
- 2026-05-31 00:16 UTCEPSS rescore
- 2026-05-31 00:16 UTCEPSS rescore
- 2026-05-29 13:44 UTCEPSS rescore
- 2026-05-29 13:44 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-27 13:40 UTCEPSS rescore
- 2026-05-27 13:40 UTCEPSS rescore
- 2026-05-26 13:44 UTCEPSS rescore
- 2026-05-26 07:18 UTCEPSS rescore
- 2026-05-21 22:43 UTCEPSS rescore
- 2026-05-20 22:38 UTCEPSS rescore
Frequently asked(5)
What is CVE-2026-6970?
When was CVE-2026-6970 disclosed?
Is CVE-2026-6970 actively exploited?
What is the CVSS score of CVE-2026-6970?
How do I remediate CVE-2026-6970?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-6970
Is Your Infrastructure Affected by CVE-2026-6970?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.