Skip to content
Critical Authentication Bypass Vulnerability in Ubuntu's Booth Component

Critical Authentication Bypass Vulnerability in Ubuntu's Booth Component

First seen 29 Sep 2026, 21:04 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 21:05 UTC
  • •Critical authentication bypass vulnerability in Ubuntu's Booth component.
  • •Remote attackers can exploit the flaw to gain unintended access to network services.
  • •Users must update to specific package versions and restart Booth to mitigate risks.

A serious authentication bypass vulnerability has been discovered in the Booth component of Ubuntu, affecting versions 18.04, 20.04, 22.04, and 24.04 LTS. The flaw arises from improper validation of message authentication codes, potentially allowing remote attackers to bypass authentication and gain unintended access to network services. CISA has confirmed the exploitation of this flaw, prompting urgent advisories for system updates. Users are advised to update their systems to the specified package versions to mitigate the risk. Affected users should restart Booth after applying the updates to ensure all changes take effect. Ubuntu Pro users have access to long-term security coverage for the affected packages. The vulnerability is cataloged under USN-8832-1, with specific package versions provided for each Ubuntu LTS release. Immediate action is recommended to prevent unauthorized access.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-28
USN-8832-1 advisory published
Ubuntu published an advisory detailing the Booth vulnerability and its potential impact on users.
Ubuntu
2026-09-29
CISA confirms exploitation
CISA confirmed that the Booth vulnerability is being actively exploited in the wild, urging users to apply patches immediately.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Ubuntu in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed