CVE-2026-31979Disclosure(himmelblau-idm / himmelblau)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch himmelblau-idm himmelblau systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Prior to 3.1.0 and 2.3.8, the himmelblaud-tasks daemon, running as root, writes Kerberos cache files under /tmp/krb5cc_<uid> without symlink protections. Since commit 87a51ee, PrivateTmp is explicitly removed from the tasks daemon's systemd hardening, exposing it to the host /tmp. A local user can exploit this via symlink attacks to chown or overwrite arbitrary files, achieving local privilege escalation. This vulnerability is fixed in 3.1.0 and 2.3.8.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • himmelblau

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 2 mentions (2026-03-11); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Products
himmelblau

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-11: 2Mentions · 2026-03-20: 1Mentions · 2026-03-23: 1Mentions · 2026-04-24: 1PoC Mentioned / Linked · 2026-03-23: 1Patch / Workaround · 2026-03-11: 2Patch / Workaround · 2026-03-20: 1Technical Details · 2026-03-11: 2Technical Details · 2026-03-20: 1Technical Details · 2026-03-23: 1Technical Details · 2026-04-24: 103-1103-2003-2304-24
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-112
Disclosure1Patch1
2026-03-201
Patch1
2026-03-231
Disclosure1
2026-04-241
Disclosure1
Full discourse5 posts
  • Andre Gironda@AndreGironda
    Disclosure

    CVE-2026-31979 the symlink trap root privilege escalation in Himmelblau -- https://www.akamai.com/blog/security-research/cve-2026-31979-symlink-root-privilege-escalation-himmelblau

    Post summary

    A new root‑privilege escalation flaw (symlink trap) in Himmelblau has been disclosed via an Akamai blog post, but no exploit code, active attacks, or patches are cited.

    00020150
    3.6K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-31979: HIGH] Himmelblau security vulnerability fixed in version 3.1.0 and 2.3.8. Root daemon exposed to symlink attacks, allowing local privilege escalation on Microsoft Azure Entra ID and Intune.#cve,CVE-2026-31979,#cybersecurity https://cvefind.com/CVE-2026-31979

    Post summary

    The post announces that CVE-2026-31979, a high‑severity privilege‑escalation flaw in the Himmelblau root daemon, has been patched in versions 3.1.0 and 2.3.8.

    0100046
    600 followersView on X
  • アカマイ・テクノロジーズ@akamai_jp
    Disclosure

    Akamai 最新ブログ:CVE-2026-31979:シンボリックリンクの罠 — Himmelblau における root 権限の昇格 深刻度の高い脆弱性である CVE-2026-31979 は、特定の Himmelblau の導入環境に影響を及ぼします。直ちに対策を講じることをお勧めします。 詳しくはこちら▼ https://ow.ly/o3wY50YKKog

    Post summary

    A blog post discloses CVE-2026-31979, a high‑severity root‑privilege escalation vulnerability triggered by a symbolic link trap in Himmelblau environments, and urges immediate remediation.

    00000174
    1.5K followersView on X
  • sgsecnet@sgsecnet
    Patch

    🚨 Critical Update: Root Escalation in Himmelblau (CVE-2026-31979) Akamai’s latest research confirms a Root Privilege Escalation in the Himmelblau identity suite. The Technical Hook: A classic TOCTOU (Time-of-Check to Time-of-Use) symlink race. By swapping a Kerberos cache file for a symlink to /etc/shadow, an unprivileged user can seize control of system credentials. The Fix: Update to v3.1.0 immediately. This version restores critical PrivateTmp systemd hardening, isolating the service from host-level symlink attacks. Why it matters: In managed environments, a single compromised node can expose the entire fleet's identity infrastructure. Full Analysis: https://www.akamai.com/blog/security-research/cve-2026-31979-symlink-root-privilege-escalation-himmelblau #CyberSecurity #ThreatHunting #LinuxSecurity #Akamai #CloudSecurity

    Post summary

    The announcement focuses on a critical root privilege escalation in the Himmelblau suite, providing a detailed vulnerability description and an immediate patch recommendation.

    0000048
    39 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31979 Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Prior to 3.1.0 and 2.3.8, the himmelblaud-tasks daemon, running as root, writes Kerbe… https://www.cve.org/CVERecord?id=CVE-2026-31979

    Post summary

    A new CVE-2026-31979 vulnerability is disclosed for Himmelblau, affecting versions before 3.1.0 and 2.3.8; the flaw involves the himmelblaud‑tasks daemon running as root writing Kerberos data, with newer releases presumably patching the issue.

    00000155
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphimmelblau-idmhimmelblau---

Explore more