Incorrect Authorization in Linux-Gaming PortProtonQt Allows Unauthorized Access
CVE-2026-59678

7.1HIGH

Key Information:

Vendor
CVE Published:
23 July 2026

What is CVE-2026-59678?

An incorrect authorization vulnerability in Linux-Gaming's PortProtonQt allows unauthorized users to mount and unmount arbitrary file systems. Additionally, it enables modifications to the network configuration through NetworkManager, potentially leading to security risks and unauthorized access to sensitive data.

Affected Version(s)

PortProtonQt 0 < 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Matthias Gerstner of SUSE
.