CVE-2026-31979 is a local privilege escalation vulnerability affecting the Himmelblau interoperability suite (himmelblau_idm and himmelblau) prior to versions 3.1.0 and 2.3.8. It allows a local user with low privileges to achieve root access by exploiting symlink attacks against the `himmelblaud-tasks` daemon, which insecurely writes Kerberos cache files to `/tmp` without proper protections. With a CVSS score of 7.8 (High), this vulnerability enables arbitrary file overwrite or ownership changes, leading to full system compromise. There is currently no evidence of active exploitation, nor are public exploit modules available on platforms like Metasploit or ExploitDB. Its very low EPSS score and limited community discussion suggest a low probability of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, < 2.3.8CPE matchmatch criteria | cpe:2.3:a:himmelblau-idm:himmelblau:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.1.0CPE matchmatch criteria | cpe:2.3:a:himmelblau-idm:himmelblau:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.