CVE-2026-25704CWE-271CWE-367

Incomplete privilege drop for com.system76.CosmicGreeter.GetUserData

Medium · published March 30, 2026

CVSS v4.0
5.8
EPSS
0%
Percentile
0.4
In the wild
Unconfirmed
What it is

A Privilege Dropping / Lowering Errors/Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in  cosmic-greeter can allow an attacker to regain privileges that should have been dropped and abuse them in the racy checking logic.

This issue affects cosmic-greeter before https://github.Com/pop-os/cosmic-greeter/pull/426.

The record
Technical detail
CVSS v4.0
5.8 · MEDIUM
Vector
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
EPSS
0.00088 · 0.4th percentile
Weaknesses
CWE-271 · Privilege Dropping / Lowering Errors; CWE-367 · Time-of-check Time-of-use (TOCTOU) Race Condition
Published
2026-03-30T07:44Z
EPSS history
Timeline
  • 30 MAR 07:44Z
    Incomplete privilege drop for com.system76.CosmicGreeter.GetUserData
    cvelistv5