SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-75037

HIGH · CVSS 7 EPSS 0.11% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A vulnerability in the Polkit authentication mechanism on Linux systems allows for an authentication bypass due to improper handling of Unix process subjects and peer PIDs in the LACT component, affecting versions up to 0.10.0. This flaw could enable unauthorized users to gain elevated privileges, potentially compromising system integrity and security. System administrators and security teams managing Linux environments should prioritize applying the fix to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75037
Severity
HIGH
CVSS
7
EPSS
0.11%
Linux

Original NVD Description

Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT on Linux allows an Authentication Bypass. This issue affects LACT through 0.10.0. Fixed by commit d0478fe42c2219454e272f96b1cbd29ab37ee566.