CVE-2026-6970Disclosure

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

authd prior to version 0.6.4 contains a logic error in primary group ID assignment that can lead to local privilege escalation. When a user's primary group ID (GID) differs from their UID, either because the account was created with authd prior to version 0.5.4 or because the primary group was manually changed via the `authctl group set-gid` command, and the user's identity provider record is updated, authd incorrectly resets the user's primary group ID to their UID upon next login. This causes newly created files and directories to be owned by the wrong group, causing denial of service issues, and potentially granting unintended access to other local users and allowing local privilege escalation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-842

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-27); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-27: 2Mentions · 2026-05-02: 1Mentions · 2026-05-06: 1Patch / Workaround · 2026-04-27: 1Patch / Workaround · 2026-05-02: 1Technical Details · 2026-04-27: 2Technical Details · 2026-05-02: 1Technical Details · 2026-05-06: 104-2705-0205-06
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-272
Disclosure2
2026-05-021
Patch1
2026-05-061
Disclosure1
Full discourse4 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 authd, Local Privilege Escalation, #CVE-2026-6970 (High) https://dailycve.com/authd-local-privilege-escalation-cve-2026-6970-high/

    Post summary

    The post announces a high‑severity local privilege escalation flaw in authd (CVE-2026-6970), offering only basic vulnerability details with no PoC, exploit, patch, or active‑exploitation evidence.

    0000037
    196 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    Authd CVE-2026-6970: Local privilege escalation. GIDs reset to UIDs on login, breaking access and opening doors. Patch to 0.6.4 now. #LPE #LinuxSec #authd #devops #devsecops #developers Info: https://www.valtersit.com/cve/2026/04/cve-2026-6970/

    Post summary

    The post announces a local privilege escalation flaw (CVE‑2026‑6970) and notes a patch (version 0.6.4) is available, but offers no exploit code or evidence of active attacks.

    0000044
    889 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6970 authd prior to version 0.6.4 contains a logic error in primary group ID assignment that can lead to local privilege escalation. When a user's primary group ID (GID) dif… https://www.cve.org/CVERecord?id=CVE-2026-6970

    Post summary

    CVE-2026-6970 is disclosed as a logic error in group ID handling that allows local privilege escalation, with no exploit code, patch, or active exploitation mentioned.

    0000075
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6970 Local Privilege Escalation via Primary Group ID Logic Error in authd Prior to 0.6.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6970

    Post summary

    The text announces CVE-2026-6970, describing a local privilege escalation flaw in authd before version 0.6.4, and implies a patch in version 0.6.4.

    0000039
    4.0K followersView on X

Explore more