Junglewise Threat Intelligence

CVE-2026-79617: Pardus LightDM Greeter permission assignment vulnerability

CVE-2026-79617 · Severity: high · CVSS 7.1 · Published 2026-09-09

Executive brief

Pardus LightDM Greeter is the login screen component used in the Pardus Linux distribution. An incorrect permission configuration in versions before 0.4.15 allows attackers to exploit access control mechanisms, potentially gaining unauthorized access to the system during or after the login process.

Technical details

This vulnerability is classified as an Incorrect Permission Assignment for Critical Resource (CWE-732). The LightDM Greeter component fails to properly enforce access controls on critical resources, allowing an attacker with local access to exploit misconfigured permissions. No network access is required; exploitation occurs on the local system where the vulnerable greeter is running. An attacker can leverage this to escalate privileges or bypass authentication controls. The issue is fixed in version 0.4.15 and later.

Affected products

  • TÜBİTAK BİLGEM Pardus LightDM Greeter before 0.4.15

Timeline

  • 2026-09-09: disclosed

References