PT-2026-51250 · Freedesktop.Org · Xdg-Desktop-Portal
CVE-2026-55888
·
Published
2026-06-21
·
Updated
2026-07-19
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
xdg-desktop-portal versions prior to 1.22.1
Description
xdg-desktop-portal exposes D-Bus interfaces under the name 'org.freedesktop.portal.Desktop' and object path '/org/freedesktop/portal/desktop' to provide APIs for file access, opening URIs, and printing. A memory error and a potential race condition within the D-Bus services allow a sandboxed application, such as those using Flatpak or Snap, to escape its sandbox. This enables the application to gain privileges equivalent to a standard system package, allowing it to access system applications and read or modify user files.
Recommendations
Update xdg-desktop-portal to version 1.22.1.
Restrict the privileges of the xdg-desktop-portal process using SELinux or AppArmor to minimize potential impact.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xdg-Desktop-Portal