Sceawere
Vulnerability Detail
CVE-2026-79617UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Pardus LightDM Greeter Permission Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 1d ago
- Vendor
- TÜBİTAK BİLGEM Software Technologies Research…
- Product
- Pardus LightDM Greeter
- Attack Type
- CWE-732 Incorrect Permission Assignment for Critical Resource
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Incorrect Permission Assignment for Critical Resource vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus LightDM Greeter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pardus LightDM Greeter: before 0.4.15.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-09-09T15:17:09.543Z",
"pubdate": "2026-09-09T15:17:09.543Z",
"executiveSummary": "This vulnerability involves an Incorrect Permission Assignment for Critical Resource within the Pardus LightDM Greeter component of the TÜBİTAK BİLGEM Pardus operating system.\nThe flaw allows unauthorized users to exploit incorrectly configured access control security levels, potentially leading to unauthorized system resource manipulation or privilege escalation.\nAffected versions include Pardus LightDM Greeter prior to 0.4.15.\nThe vulnerability poses a significant risk to system integrity, as it permits attackers with local access to bypass established security boundaries.\nSuccessful exploitation requires local access to the system, enabling an unprivileged attacker to interact with sensitive resources typically restricted to higher-privileged contexts.\nThe nature of the defect centers on improper file system or IPC permission settings that fail to enforce the principle of least privilege.",
"technicalDetails": "The root cause of this vulnerability lies in the improper configuration of file system permissions or access control lists (ACLs) associated with critical resources managed by the Pardus LightDM Greeter service.\nThe LightDM Greeter is responsible for rendering the login interface and managing initial user sessions; by failing to correctly restrict access to its underlying configuration files or temporary data structures, the greeter creates a path for local privilege escalation.\nIn a standard operating environment, services like LightDM Greeter should operate with strictly defined privileges. When these permissions are misassigned, an unprivileged user can modify configuration files or intercept inter-process communication (IPC) signals that the greeter relies upon.\nThe attack flow typically begins with an unprivileged local user identifying a resource, such as a configuration file or a socket managed by the LightDM Greeter, that lacks restrictive owner or group permissions. By exploiting these overly permissive settings, an attacker may inject arbitrary input, modify behavioral parameters, or intercept sensitive authentication-related data processed during the greeter's initialization phase.\nThe vulnerability is primarily triggered during the greeter's execution cycle, where the lack of proper validation of resource access allows the system to inadvertently grant excessive capabilities to the user space. This interaction effectively bypasses the expected access control security levels, allowing an attacker to manipulate the greeter to execute commands or leak information that should be inaccessible.\nBecause the vulnerability pertains to the initialization and execution of the Greeter, the impact is localized to the session-management layer. Post-exploitation, an attacker could potentially influence the graphical login process to gain escalated access or access sensitive session information, undermining the security posture of the local host environment.\nThe scope of this vulnerability is limited to the Pardus LightDM Greeter component, specifically those versions prior to 0.4.15, and requires local logical access, excluding remote network-based exploitation vectors unless chained with other vulnerabilities."
}