D-Bus Broadcast Message Filtering Flaw in xdg-dbus-proxy from Red Hat
CVE-2026-93676

3.2LOW

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
18 September 2026

What is CVE-2026-93676?

The xdg-dbus-proxy has a vulnerability where it fails to properly filter D-Bus broadcast messages, allowing sandboxed Flatpak applications to intercept broadcast signals on both the D-Bus session bus and the AT-SPI bus. This flaw compromises configured restrictions related to paths, interfaces, and members, potentially allowing malicious applications to access sensitive information that should be protected, leading to unauthorized data exposure.

References

CVSS V3.1

Score:
3.2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.