CVE-2026-31979
Last modified
CVE-2026-31979 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Prior to 3.1.0 and 2.3.8, the himmelblaud-tasks daemon, running as root, writes Kerberos cache files under /tmp/krb5cc_<uid> without symlink protections. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Prior to 3.1.0 and 2.3.8, the himmelblaud-tasks daemon, running as root, writes Kerberos cache files under /tmp/krb5cc_<uid> without symlink protections. Since commit 87a51ee, PrivateTmp is explicitly removed from the tasks daemon's systemd hardening, exposing it to the host /tmp. A local user can exploit this via symlink attacks to chown or overwrite arbitrary files, achieving local privilege escalation. This vulnerability is fixed in 3.1.0 and 2.3.8.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Himmelblau-Idm | Himmelblau | >= 1.0.0, < 2.3.8 |
| Himmelblau-Idm | Himmelblau | >= 3.0.0, < 3.1.0 |
References
- https://github.com/himmelblau-idm/himmelblau/security/advisories/GHSA-44wm-q286-ghq3Exploit, Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-31979?
How severe is CVE-2026-31979?
How do I fix CVE-2026-31979?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-31972SAMtools is a program for reading, manipulating and writing …9.8
- CVE-2026-31973SAMtools is a program for reading, manipulating and writing …7.5
- CVE-2026-31974OpenProject is an open-source, web-based project management …4.3
- CVE-2026-31975Cloud CLI (aka Claude Code UI) is a desktop and mobile UI fo…9.8
- CVE-2026-31976xygeni-action is the GitHub Action for Xygeni Scanner. On Ma…9.8
- CVE-2026-31978motionEye (mEye) is an online interface for motion software,…6.5
- CVE-2026-3198MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails…6.5
- CVE-2026-31981A Stored HTML Injection vulnerability was discovered in the …4.8
- CVE-2026-31982An Open Redirect vulnerability was discovered in the SAML Si…7.1
- CVE-2026-31983A Missing Authentication vulnerability was discovered in the…6.9
- CVE-2026-31984A denial-of-service vulnerability caused by unbounded resour…8.7
- CVE-2026-31985When the upstream Guardian or CMC was configured in the Remo…8.3
Are you affected by CVE-2026-31979?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
