Description
xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bus that should be restricted, potentially exposing sensitive information to unauthorized applications.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Workaround
Affects versions 0.1.6 and 0.1.7. Fixed in 0.1.8.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 18 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bus that should be restricted, potentially exposing sensitive information to unauthorized applications. | |
| Title | Xdg-dbus-proxy: xdg-dbus-proxy: filtering for broadcast messages bypasses path/interface/member checks | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-284 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-18T15:10:34.262Z
Reserved: 2026-09-18T13:51:38.463Z
Link: CVE-2026-93676
No data.
Status : Awaiting Analysis
Published: 2026-09-18T15:17:22.813
Modified: 2026-09-18T19:06:08.407
Link: CVE-2026-93676
No data.
OpenCVE Enrichment
No data.
Weaknesses