Description
An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager.






This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe.
Published: 2026-07-23
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in PortProtonQt arises from an incorrect authorization check that lets any local user mount or unmount arbitrary filesystems and modify the system’s network configuration through NetworkManager. The core weakness is a lack of access control, identified as CWE-863.

Affected Systems

Linux‑Gaming PortProtonQt versions before commit 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe are affected. No other vendors or products are listed as impacted.

Risk and Exploitability

The CVSS score of 7.1 indicates a high impact, while the EPSS score of less than 1% shows that exploitation is currently unlikely. Because the flaw is local, an attacker must have an account on the target system to exploit it, and the issue is not included in the CISA KEV catalog. A standard user can mount filesystems and modify network settings, thereby gaining unauthorized local privileges.

Generated by OpenCVE AI on August 3, 2026 at 22:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PortProtonQt to a version newer than commit 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe
  • Restrict mount capabilities to privileged users by ensuring correct permission settings on mount utilities
  • Review and harden NetworkManager configuration to prevent unauthorized users from modifying network settings

Generated by OpenCVE AI on August 3, 2026 at 22:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Linux-gaming
Linux-gaming portprotonqt
Vendors & Products Linux-gaming
Linux-gaming portprotonqt

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Description An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe.
Title portprotonqt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Linux-gaming Portprotonqt
cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2026-07-23T14:01:55.520Z

Reserved: 2026-07-06T11:59:28.118Z

Link: CVE-2026-59678

cve-icon Vulnrichment

Updated: 2026-07-23T14:01:52.793Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T08:16:25.003

Modified: 2026-07-23T15:26:39.980

Link: CVE-2026-59678

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:00:04Z

Weaknesses