rootpwn

low · CVSS v3 3.2

CVE-2026-93676

xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictio…

Description

xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bus that should be restricted, potentially exposing sensitive information to unauthorized applications.

Scores

Severity
low
CVSS v2
2.1
CVSS v3
3.2
CVSS v4
EPSS

← All CVEs