CVE-2024-9313: Canonical Authd

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation with it, including authenticating as them.

Affected products

  • Canonical Authd: before 0.3.5 (fixed in 0.3.5)

Published 2024-10-03. Last modified 2026-06-17.