PT-2026-51250 · Freedesktop.Org · Xdg-Desktop-Portal

CVE-2026-55888

·

Published

2026-06-21

·

Updated

2026-07-19

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions xdg-desktop-portal versions prior to 1.22.1
Description xdg-desktop-portal exposes D-Bus interfaces under the name 'org.freedesktop.portal.Desktop' and object path '/org/freedesktop/portal/desktop' to provide APIs for file access, opening URIs, and printing. A memory error and a potential race condition within the D-Bus services allow a sandboxed application, such as those using Flatpak or Snap, to escape its sandbox. This enables the application to gain privileges equivalent to a standard system package, allowing it to access system applications and read or modify user files.
Recommendations Update xdg-desktop-portal to version 1.22.1. Restrict the privileges of the xdg-desktop-portal process using SELinux or AppArmor to minimize potential impact.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-55888
OESA-2026-2998
OESA-2026-2999
OESA-2026-3000

Affected Products

Xdg-Desktop-Portal