High severity8.8NVD Advisory· Published Mar 11, 2026· Updated Jun 17, 2026
CVE-2026-31979
CVE-2026-31979
Description
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Prior to 3.1.0 and 2.3.8, the himmelblaud-tasks daemon, running as root, writes Kerberos cache files under /tmp/krb5cc_ without symlink protections. Since commit 87a51ee, PrivateTmp is explicitly removed from the tasks daemon's systemd hardening, exposing it to the host /tmp. A local user can exploit this via symlink attacks to chown or overwrite arbitrary files, achieving local privilege escalation. This vulnerability is fixed in 3.1.0 and 2.3.8.
Affected products
8cpe:2.3:a:himmelblau-idm:himmelblau:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:himmelblau-idm:himmelblau:*:*:*:*:*:*:*:*range: >=1.0.0,<2.3.8
- (no CPE)range: <3.1.0, <2.3.8
- (no CPE)range: >= 1.0.0, < 2.3.8
- osv-coords5 versionspkg:rpm/opensuse/himmelblau&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/himmelblau&distro=openSUSE%20Tumbleweedpkg:rpm/suse/himmelblau&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7pkg:rpm/suse/himmelblau&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/himmelblau&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0
< 2.3.8+git0.dec3693-160000.1.1+ 4 more
- (no CPE)range: < 2.3.8+git0.dec3693-160000.1.1
- (no CPE)range: < 2.3.8+git0.dec3693-1.1
- (no CPE)range: < 2.3.9+git0.a9fd29b-150700.3.15.1
- (no CPE)range: < 2.3.8+git0.dec3693-160000.1.1
- (no CPE)range: < 2.3.8+git0.dec3693-160000.1.1
Patches
Vulnerability mechanics
References
1- github.com/himmelblau-idm/himmelblau/security/advisories/GHSA-44wm-q286-ghq3nvdExploitMitigationVendor Advisory
News mentions
0No linked articles in our index yet.