CVE-2026-25704

Incomplete privilege drop for com.system76.CosmicGreeter.GetUserData

Title source: cna

Description

A Privilege Dropping / Lowering Errors/Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in  cosmic-greeter can allow an attacker to regain privileges that should have been dropped and abuse them in the racy checking logic. This issue affects cosmic-greeter before https://github.Com/pop-os/cosmic-greeter/pull/426.

Scores

EPSS 0.0001
EPSS Percentile 1.6%

Details

CWE
CWE-271 CWE-367
Status published
Products (1)
pop-os/cosmic-greeter ? - https://github.com/pop-os/cosmic-greeter/pull/426
Published Mar 30, 2026
Tracked Since Mar 30, 2026