CVE-2025-6018General(suse / pam-config)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for suse pam-config systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM). This flaw allows an unprivileged local attacker (for example, a user logged in via SSH) to obtain the elevated privileges normally reserved for a physically present, "allow_active" user. The highest risk is that the attacker can then perform all allow_active yes Polkit actions, which are typically restricted to console users, potentially gaining unauthorized control over system configurations, services, or other sensitive operations.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pam-config

Threat summary

  • Public PoC and exploit tooling are both present
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-02-08); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
pam-config

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-08: 1Mentions · 2026-02-09: 1Mentions · 2026-02-12: 1Mentions · 2026-05-16: 1PoC Mentioned / Linked · 2026-02-09: 1PoC Mentioned / Linked · 2026-05-16: 1Exploit Tool / Code · 2026-02-09: 1Exploit Tool / Code · 2026-05-16: 1Technical Details · 2026-02-08: 1Technical Details · 2026-02-09: 1Technical Details · 2026-05-16: 102-0802-0902-1205-16
Signal classification2 categories
General
250.0%
Exploit
250.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-081
General1
2026-02-091
Exploit1
2026-02-121
General1
2026-05-161
Exploit1
Full discourse4 posts
  • DFIR Radar@DFIR_Radar
    Exploit

    Critical directory traversal in Pterodactyl Panel v1.11.10 leads to unauthenticated RCE via PHP-PEAR exploitation chain. CVE-2025-49132 combines with PEAR pearcmd technique enabling arbitrary webshell deployment. Key technical details: • Endpoint /locales/locale.json bypasses auth middleware, accepts unsanitized locale/namespace parameters • Path traversal: locale=../../../../../usr/share/php/PEAR&namespace=pearcmd enables arbitrary .php file inclusion • PEAR pearcmd.php accepts config-create command via register_argc_argv, writes attacker-controlled content to disk • Payload: `<?=system($_REQUEST[0]);?>` creates webshell at /tmp/shell.php accessible via LFI Attack chain methodology: • Initial recon reveals Pterodactyl Panel v1.11.10 with PHP-PEAR enabled • Directory traversal to include pearcmd.php with malicious config creation • Second request includes written webshell for command execution • Database credential extraction leads to bcrypt hash cracking: !QAZ2wsx • Privilege escalation via CVE-2025-6018 (PAM environment bypass) + CVE-2025-6019 (libblockdev/udisks XFS mounting) Hunt for HTTP requests to `/locales/locale.json` with `../` sequences in locale parameter and suspicious namespace values targeting pearcmd.php. #DFIR_Radar

    Post summary

    The article outlines a detailed, functional exploitation chain for CVE-2025-49132, providing PoC code and technical steps but no indication of active attacks or mitigation.

    110221.8K
    1.8K followersView on X
  • IT Cat ✈️@itcaat
    General

    @gaxeliy @Wandrovik Также уязвимости Linux (я что вам какая то шутка ) CVE-2025-38561, CVE-2025-6018, CVE-2025-6019, CVE-2025-32463, CVE-2026-24061

    Post summary

    The tweet merely lists several Linux CVE identifiers without offering any additional technical or contextual information.

    1001049
    1.5K followersView on X
  • Michael Venturella@Mr_Venturella
    Exploit

    Created my first CVE exploit for CVE-2025-6018 &amp; CVE-2025-6019: Local Privilege Escalation. Check it out here on github https://github.com/MichaelVenturella/CVE-2025-6018-6019-PoC

    Post summary

    The user has published exploit code for CVE‑2025‑6018 and CVE‑2025‑6019 on GitHub, demonstrating local privilege escalation.

    0001097
    15 followersView on X
  • Brian_Bundi@bundibrianx
    General

    Just finished a deep dive into Pterodactyl on HackTheBox. This one was a beast—chaining CVE-2025-49132 for the initial foothold, then navigating PAM environment injection (CVE-2025-6018) and a UDisks2 LPE (CVE-2025-6019) to hit root. https://labs.hackthebox.com/achievement/machine/2252974/832 #HackTheBox #HTB

    Post summary

    The write‑up describes chaining CVE‑2025‑49132, CVE‑2025‑6018, and CVE‑2025‑6019 on a HackTheBox machine, providing only high‑level technical details without any PoC, exploit code, patch, or evidence of active exploitation.

    0001078
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsusepam-config1.1.8-24.71.1--

Explore more