A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to be part of the root group in the context of that SSH session.
https://github.com/ubuntu/authd/security/advisories/GHSA-g8qw-mgjx-rwjr