Junglewise Threat Intelligence

CVE-2026-25710: KDE plasma-login-manager privilege escalation in plasmaloginauthhelper

CVE-2026-25710 · Severity: info · CVSS 7 · Published 2026-05-13

Vendors: Kde.

Executive brief

A security vulnerability exists in the KDE Plasma login manager, a component responsible for managing the login screen and user sessions. A privileged helper tool within this component fails to properly restrict its actions, allowing a compromised service account to gain full control over the system. This could lead to unauthorized access to sensitive files, system-wide data deletion, or a complete takeover of the computer by a local attacker.

Technical details

The 'plasmaloginauthhelper' D-Bus service in KDE's plasma-login-manager (specifically version 6.6.2) runs with root privileges but performs file operations within the '/var/lib/plasmalogin' directory without dropping privileges to the service user. This leads to multiple vulnerabilities: the 'sync()' method performs insecure chown() calls vulnerable to symlink attacks; the 'reset()' method uses 'QDir::removeRecursively()', which follows symlinks to delete arbitrary system directories; and the 'save()' method is vulnerable to a race condition during directory creation. While these actions typically require 'auth_admin' Polkit authentication, the lack of privilege separation allows a compromised 'plasmalogin' service account to escalate to full root access. A fix was scheduled for the May 12, 2026, Plasma release.

Affected products

  • KDE plasma-login-manager 6.6.2

Timeline

  • 2026-03-27: disclosed: Initial discovery and internal reporting at SUSE.
  • 2026-04-27: advisory: Public advisory released by SUSE security team.
  • 2026-05-12: patched: Planned upstream security release.
  • 2026-05-13: other: CVE published to NVD.

References