7
/ 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
The new upstream added a privileged D-Bus
helper called plasmaloginauthhelper, which suffers from multiple issues, e.g.aA compromised plasmalogin service account can chown() arbitrary files in the system.
helper called plasmaloginauthhelper, which suffers from multiple issues, e.g.aA compromised plasmalogin service account can chown() arbitrary files in the system.
Basic Information
ID
CVE-2026-25710
Source
suse
Published
May 13, 2026 at 08:44
Modified
May 13, 2026 at 09:04
Affected Product
Vendor
KDE
Product
plasma-login-manager
Affected Versions
KDE plasma-login-manager 0