CVE-2024-6107: Canonical Metal As A Service

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been addressed in MAAS and updated in the corresponding snaps.

Affected products

  • Canonical Metal As A Service: from 3.1.0, before 3.1.4 (fixed in 3.1.4); from 3.2.0, before 3.2.11 (fixed in 3.2.11); from 3.3.0, before 3.3.8 (fixed in 3.3.8); from 3.4.0, before 3.4.4 (fixed in 3.4.4); version 3.5.0 only

Published 2025-07-21. Last modified 2026-06-17.