Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →
All 2 checks on this page
- 7.2 Local User and Group Settings
- Ensure no duplicate UIDs exist
- Ensure no duplicate user names exist
7.2 Local User and Group Settings
Ensure no duplicate UIDs exist
Finding: This account's UID is shared with another account.
Checks whether another account in the account database shares this account's UID.
This rule fails for an account whose UID is also assigned to another account.
Rationale: Accounts must have unique UIDs for accountability; a shared UID lets one account access another account's files and privileges.
Impact: Reassigning a UID requires updating ownership of the affected user's files.
Scope: Ubuntu 24.04 and later endpoints.
Remediation
For each set of accounts sharing a UID, assign a new unique UID to all but one with usermod -u <newUID> <name>.
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure no duplicate user names exist
Finding: This account's username is shared with another account.
Checks whether another account in the account database uses this account's username.
This rule fails for an account whose username also appears under another UID.
Rationale: Duplicate user names effectively share the first matching UID, so logins can resolve to an unintended identity and shared file access.
Impact: Renaming a user may require updating references to the old name.
Scope: Ubuntu 24.04 and later endpoints.
Remediation
For each duplicated username, rename all but one account to a unique name with usermod -l <newName> <oldName>.
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)