Polkit Authentication Vulnerability in OpenSUSE Products
CVE-2025-14338

8.5HIGH

Key Information:

Vendor
CVE Published:
14 January 2026

Badges

📰 News Worthy

What is CVE-2025-14338?

A vulnerability exists in Polkit, which may allow unauthorized access due to authentication being disabled by default, combined with a race condition in authorization checks in versions prior to v0.69.0. This loophole could lead to elevated privileges for an attacker, mimicking the issues previously documented in earlier vulnerabilities. It is crucial for users to ensure they are running the latest version to safeguard their systems from potential exploits.

Affected Version(s)

inputplumber ? < 0.63.0

News Articles

Critical InputPlumber Vulnerability Enables UI Input Injection and Denial-of-Service

InputPlumber is primarily utilized in Linux gaming environments and is integrated into Valve's SteamOS platform.

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • 📰

    First article discovered by Cyber Press

  • Vulnerability Reserved

Credit

Matthias Gerstner of SUSE
.