{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3atubitakpardus_lightdm_greeter/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:tubitak:pardus_lightdm_greeter:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-79617"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Pardus LightDM Greeter (\u003c 0.4.15)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["TÜBİTAK BİLGEM"],"content_html":"\u003cp\u003eThe Pardus LightDM Greeter, a component developed by the TÜBİTAK BİLGEM Software Technologies Research Institute, contains an incorrect permission assignment vulnerability identified as CVE-2026-79617. This flaw stems from improperly configured access control security levels within the greeter process. An attacker with local access to the system can exploit this misconfiguration to bypass intended security constraints, potentially resulting in unauthorized privilege escalation. The vulnerability affects all versions of the Pardus LightDM Greeter prior to 0.4.15. Defenders should prioritize updating the greeter component to the patched version, as unauthorized access to the login interface context can provide a vector for further system compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a significant risk to host systems running the affected Pardus LightDM Greeter, as successful exploitation enables local privilege escalation. This could allow an unprivileged local user to gain higher-level permissions, compromising the integrity and confidentiality of the host operating system. Organizations utilizing Pardus Linux distributions where this specific greeter component is active are at risk if they remain on versions earlier than 0.4.15.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Pardus LightDM Greeter component to version 0.4.15 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit local system access logs for unauthorized attempts to interact with or restart the LightDM service.\u003c/li\u003e\n\u003cli\u003eReview access control lists on critical system configuration files associated with the greeter process.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-09T16:58:28Z","date_published":"2026-09-09T16:58:28Z","id":"https://feed.craftedsignal.io/briefs/2026-09-pardus-lightdm-vuln/","summary":"An incorrect permission assignment vulnerability in the Pardus LightDM Greeter component, tracked as CVE-2026-79617, allows local attackers to exploit access control misconfigurations for privilege escalation.","title":"Privilege Escalation in Pardus LightDM Greeter via Incorrect Permissions","url":"https://feed.craftedsignal.io/briefs/2026-09-pardus-lightdm-vuln/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:tubitak:pardus_lightdm_greeter:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}