Executive brief
A security vulnerability exists in the KDE Plasma login manager, a component responsible for managing the login screen and user sessions. A privileged helper tool within this component fails to properly restrict its actions, allowing a compromised service account to gain full control over the system. This could lead to unauthorized access to sensitive files, system-wide data deletion, or a complete takeover of the computer by a local attacker.
Technical details
The 'plasmaloginauthhelper' D-Bus service in KDE's plasma-login-manager (specifically version 6.6.2) runs with root privileges but performs file operations within the '/var/lib/plasmalogin' directory without dropping privileges to the service user. This leads to multiple vulnerabilities: the 'sync()' method performs insecure chown() calls vulnerable to symlink attacks; the 'reset()' method uses 'QDir::removeRecursively()', which follows symlinks to delete arbitrary system directories; and the 'save()' method is vulnerable to a race condition during directory creation. While these actions typically require 'auth_admin' Polkit authentication, the lack of privilege separation allows a compromised 'plasmalogin' service account to escalate to full root access. A fix was scheduled for the May 12, 2026, Plasma release.
Affected products
- KDE plasma-login-manager 6.6.2
Timeline
- 2026-03-27: disclosed: Initial discovery and internal reporting at SUSE.
- 2026-04-27: advisory: Public advisory released by SUSE security team.
- 2026-05-12: patched: Planned upstream security release.
- 2026-05-13: other: CVE published to NVD.