Cyber Resilience

CVE-2024-9313

Canonical Authd ≤ 0.3.5

Published
03 October 2024
Modified
26 August 2025
Patch / advisory
CVSS Score v3.1 8.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0058 45th percentile
Risk Priority 65 floored blend · peak EPSS

Summary

CVE-2024-9313 is a high-severity an unspecified weakness vulnerability in Canonical Authd. Its CVSS base score is 8.8 (High).

Operationally, ranked at the 45th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation with it, including authenticating as them.

CWE(s)

Related Threats

CVEs Like This One

CVE-2025-5689Same product: Canonical Authd
CVE-2024-9312Same product: Canonical Authd
CVE-2023-5536Same vendor: Canonical
CVE-2026-32692Same vendor: Canonical
CVE-2026-3888Same vendor: Canonical
CVE-2025-0928Same vendor: Canonical
CVE-2026-47331Same vendor: Canonical
CVE-2024-29069Same vendor: Canonical
CVE-2024-8038Same vendor: Canonical
CVE-2025-54289Same vendor: Canonical

Affected Assets

canonical
authd
≤ 0.3.5

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References