Authentication Bypass Vulnerability in LACT by Linux-based Vendor
CVE-2026-75037

7.3HIGH

Key Information:

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-75037?

An authentication bypass vulnerability exists in LACT due to improper handling of UnixProcessSubject and Peer PID, which could allow unauthorized users to gain access to functionalities restricted to privileged accounts. This issue affects all versions of LACT up to 0.10.0. A patch has been implemented in recent updates to address and mitigate this security concern.

Affected Version(s)

LACT Linux 0 <= 0.10.0

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.