PT-2026-81257 · Lact · Lact
CVE-2026-75037
·
Published
2026-08-25
·
Updated
2026-08-29
CVSS v4.0
7.3
High
| Vector | AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
LACT versions prior to 0.10.1
Description
An authentication bypass exists in LACT on Linux due to the way Polkit authentication is handled based on UnixProcessSubject and Peer PID. This allows an attacker to circumvent the required authentication mechanisms.
Recommendations
Update LACT to a version that includes commit d0478fe42c2219454e272f96b1cbd29ab37ee566.
Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lact