๐Ÿ” CVE Alert

CVE-2026-94422

HIGH 8.8

xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, but it is released as a separate project and is sometimes used by other app frameworks such as Firejail.

CWE CWE-290
Published Oct 2, 2026
Last Updated Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for

Be the first to know when new high vulnerabilities are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Fedora / Fedora
0 < 0.1.9
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-94422 github.com: https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-2cgv-pwcq-wvpq github.com: https://github.com/flatpak/xdg-dbus-proxy/commit/e5702fca4dba9600721921fbca2dbc39dc5ca400 github.com: https://github.com/flatpak/xdg-dbus-proxy/commit/fc027f759316fb2a6c45648200b6f100202eb84e github.com: https://github.com/flatpak/xdg-dbus-proxy/commit/e4465a0dfe96da3b39929a30a1ac3a22b16223e3 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2542235 openwall.com: http://www.openwall.com/lists/oss-security/2026/09/23/5

Credits

๐Ÿ” refi64