authd 0.6.0 contains [a bug](https://github.com/canonical/authd/issues/1482) which can lead to an incorrect primary group ID. It affects users whose primary group ID (i.e. the GID in the user record) differs from their…
| CVE ID | CVE-2026-6970 |
| Vendor | go |
| Affected Product | github.com/canonical/authd |
| Vulnerability Type | Vulnerability |
| CVSS Score | 7.5 (HIGH) |
| Actively Exploited | ❌ No known exploitation |
| Patch Status | See Vendor Advisory → |
| Reported By | CYBERDUDEBIVASH SENTINEL APEX Intelligence (via github_advisories) |
authd 0.6.0 contains [a bug](https://github.com/canonical/authd/issues/1482) which can lead to an incorrect primary group ID. It affects users whose primary group ID (i.e. the GID in the user record) differs from their UID. There are two ways which can lead to this: 1. The user was created with authd &2 continue fi if [ "$OLD_GID" = "$GID" ]; then continue
done `` After applying the fix, affected users must log out and log back in for id, groups`, and new file GID stamping to reflect the corrected primary group. You may
Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.