Description
Incorrect Permission Assignment for Critical Resource vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus LightDM Greeter allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects Pardus LightDM Greeter: before 0.4.15.
Published: 2026-09-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch Now
AI Analysis

Impact

Pardus LightDM Greeter before version 0.4.15 has an incorrect permission assignment that allows an attacker to view display contents that should be hidden, exposing sensitive information displayed during the login process or while the user is logged in. The flaw is catalogued as a CWE‑732 weakness, which means that system resources are granted broader access than intended, leading to a confidentiality breach.

Affected Systems

The vulnerability affects TÜBİTAK BİLGEM Software Technologies Research Institute’s Pardus LightDM Greeter. All installations of Pardus using this greeter with a version earlier than 0.4.15 are impacted. The remediation version is 0.4.15 or later; no other vendors or products are listed.

Risk and Exploitability

The CVSS score of 7.1 highlights a high severity resulting primarily from the potential loss of confidential data. The EPSS score is unavailable, and the vulnerability is not currently listed in the CISA KEV catalog, indicating no known widespread exploitation. The attack vector is inferred to be on systems where the greeter is running, requiring local or privileged access to read the screen, so the risk is primarily limited to local attackers or those who can interact with the user session. The absence of publicly documented exploits suggests that the threat is low to moderate until a potential zero‑day application emerges.

Generated by OpenCVE AI on September 9, 2026 at 16:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest patch to Pardus LightDM Greeter 0.4.15 or later
  • Reconfigure the greeter to enforce correct permission settings on display output resources, ensuring only authorized users can access the screen content
  • Audit system permissions on display resources to confirm that no unauthorized groups or users can read or write screen content

Generated by OpenCVE AI on September 9, 2026 at 16:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Tubitak Bilgem Software Technologies Research Institute
Tubitak Bilgem Software Technologies Research Institute pardus Lightdm Greeter
Vendors & Products Tubitak Bilgem Software Technologies Research Institute
Tubitak Bilgem Software Technologies Research Institute pardus Lightdm Greeter

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Incorrect Permission Assignment for Critical Resource vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus LightDM Greeter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pardus LightDM Greeter: before 0.4.15.
Title Improper Access Control Leading to Display Exposure in TÜBİTAK BİLGEM's Pardus LightDM Greeter
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Tubitak Bilgem Software Technologies Research Institute Pardus Lightdm Greeter
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-09T19:16:09.062Z

Reserved: 2026-08-25T07:51:26.587Z

Link: CVE-2026-79617

cve-icon Vulnrichment

Updated: 2026-09-09T19:16:04.915Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T15:17:09.543

Modified: 2026-09-09T20:20:43.550

Link: CVE-2026-79617

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:47:59Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource