CVE-2026-25710: plasma-login-manager: Weaknesses in plasmaloginauthhelper (CVE-2026-25710)
The new upstream added a privileged D-Bus helper called plasmaloginauthhelper, which suffers from multiple issues, e.g.aA compromised plasmalogin service account can chown() arbitrary files in the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25710?
CVE-2026-25710 has a high severity rating of 7 according to the CVSS v4.0.
How do I fix CVE-2026-25710?
To address CVE-2026-25710, ensure that you update to the latest version of the KDE plasma-login-manager where the vulnerabilities have been patched.
What vulnerabilities are associated with CVE-2026-25710?
CVE-2026-25710 involves weaknesses in the plasmaloginauthhelper that could allow compromised services to modify arbitrary files on the system.
Who is affected by CVE-2026-25710?
Users of the KDE plasma-login-manager may be affected by CVE-2026-25710 due to the potential for privilege escalation.
What is plasmaloginauthhelper in relation to CVE-2026-25710?
Plasmaloginauthhelper is a privileged D-Bus helper introduced in the KDE plasma-login-manager that is vulnerable as per CVE-2026-25710.