CVE-2026-75037: Ilya-Zlobintsev Lact

High severity, CVSS 7.0. EPSS: 0.2% chance of exploitation in the next 30 days.

Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT on Linux allows an Authentication Bypass. This issue affects LACT through 0.10.0. Fixed by commit d0478fe42c2219454e272f96b1cbd29ab37ee566.

Affected products

Published 2026-08-25. Last modified 2026-09-28.