PT-2026-102983 · Firejail+2 · Firejail+2

·

CVE-2026-94422

·

Published

2026-09-28

·

Updated

2026-10-02

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions xdg-dbus-proxy versions prior to 0.1.9
Description An incorrect implementation of message filtering allows an attacker to bypass intended filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could exploit this to achieve arbitrary code execution outside its sandbox. This component is intended to be part of the sandbox boundary for Flatpak and is also utilized by other frameworks such as Firejail.
Recommendations Update to version 0.1.9 or later.

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94422
OPENSUSE-SU-2026:11913-1

Affected Products

Firejail
Flatpak
Xdg-Dbus-Proxy