CVE-2026-25710: Kde Plasma-Login-Manager
High severity, CVSS 7.0. EPSS: 0.2% chance of exploitation in the next 30 days.
The new upstream added a privileged D-Bus helper called plasmaloginauthhelper, which suffers from multiple issues, e.g.aA compromised plasmalogin service account can chown() arbitrary files in the system.
Affected products
- Kde Plasma-Login-Manager
Published 2026-05-13. Last modified 2026-06-17.