an LPE vulnerability (a Local Privilege Escalation) in the PAM configuration: an unprivileged local attacker (e.g., an attacker who logs in via sshd) can obtain the privileges of a physical "allow_active" user (i.e., a user who is physically sitting in front of the computer) and can therefore perform all the "allow_active yes" polkit actions that are normally reserved for physical users.