Description
Incorrect Permission Assignment for Critical Resource vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus LightDM Greeter allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects Pardus LightDM Greeter: before 0.4.15.
Published: 2026-09-09
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Pardus LightDM Greeter before version 0.4.15 has an incorrect permission assignment that allows an attacker to view display contents that should be hidden, exposing sensitive information displayed during the login process or while the user is logged in. The flaw is catalogued as a CWE‑732 weakness, which means that system resources are granted broader access than intended, leading to a confidentiality breach.

Affected Systems

The vulnerability affects TÜBİTAK BİLGEM Software Technologies Research Institute’s Pardus LightDM Greeter. All installations of Pardus using this greeter with a version earlier than 0.4.15 are impacted. The remediation version is 0.4.15 or later; no other vendors or products are listed.

Risk and Exploitability

The CVSS score of 7.1 highlights a high severity resulting primarily from the potential loss of confidential data. The EPSS score is unavailable, and the vulnerability is not currently listed in the CISA KEV catalog, indicating no known widespread exploitation. The attack vector is inferred to be on systems where the greeter is running, requiring local or privileged access to read the screen, so the risk is primarily limited to local attackers or those who can interact with the user session. The absence of publicly documented exploits suggests that the threat is low to moderate until a potential zero‑day application emerges.

Generated by OpenCVE AI on September 9, 2026 at 16:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch to Pardus LightDM Greeter 0.4.15 or later
  • Reconfigure the greeter to enforce correct permission settings on display output resources, ensuring only authorized users can access the screen content
  • Audit system permissions on display resources to confirm that no unauthorized groups or users can read or write screen content

Generated by OpenCVE AI on September 9, 2026 at 16:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Incorrect Permission Assignment for Critical Resource vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus LightDM Greeter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pardus LightDM Greeter: before 0.4.15.
Title Improper Access Control Leading to Display Exposure in TÜBİTAK BİLGEM's Pardus LightDM Greeter
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-09T14:11:10.836Z

Reserved: 2026-08-25T07:51:26.587Z

Link: CVE-2026-79617

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-09T15:17:09.543

Modified: 2026-09-09T15:37:49.157

Link: CVE-2026-79617

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T16:45:13Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource