GHSA-fg3j-5w9g-hmg7 · Severity: high · Ecosystem: go — authd: Primary group ID is incorrectly set to value of UID
authd prior to version 0.6.4 contains a logic error in primary group ID assignment that can lead to local privilege escalation. When a user's primary group ID (GID) differs from their UID, either because the account was created with authd prior to version 0.5.4 or because the primary group was manually changed via the `authctl group set-gid` command, and the user's identity provider record is updated, authd incorrectly resets the user's primary group ID to their UID upon next login. This causes newly created files and directories to be owned by the wrong group, causing denial of service issues, and potentially granting unintended access to other local users and allowing local privilege escalation.
Conclusion & alert: CVE-2026-6970 is rated Low Risk (29.8/100): CVSS High severity, with low exploitation likelihood (EPSS 0.11%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.01% | 0.11% | +0.10% |
| 2 | 2026-04-28 | — | 0.01% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.3 | 4.0 | HIGH |
|
— | — | [email protected] |
GHSA-fg3j-5w9g-hmg7 · Severity: high · Ecosystem: go — authd: Primary group ID is incorrectly set to value of UID
| vendor | priority | summary | link |
|---|---|---|---|
ubuntu
|
medium | CVE-2026-6970 medium priority: Ubuntu including 1 source packages (authd), 5 status rows across 5 suites (jammy, noble, questing, resolute, upstream): DNE 3, released 2. | https://ubuntu.com/security/CVE-2026-6970 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||