CVE-2025-5689: Canonical Authd
High severity, CVSS 8.5. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to be part of the root group in the context of that SSH session.
Affected products
- Canonical Authd: before 0.5.4 (fixed in 0.5.4)
Published 2025-06-16. Last modified 2026-06-17.