VendorsCanonicalauthdany version
Vulnerabilities

Canonical Authd any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2024-9313
Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation with it, including authenticating as them.
Published 2024-10-03 · Analyzed
8.8EPSS 0.006
CVE-2025-5689
Improper Permission Management in SSH Session Handling
Published 2025-06-16 · Analyzed
8.5EPSS 0.003
CVE-2024-9312
Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions. A local attacker who can register user names could spoof another user's ID and gain their privileges.
Published 2024-10-10 · Analyzed
7.5EPSS 0.003