Description
xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bus that should be restricted, potentially exposing sensitive information to unauthorized applications.
Published: 2026-09-18
Score: 3.2 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Information Disclosure via intercepted D-Bus broadcast signals
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in xdg-dbus-proxy causes it to ignore configured path, interface and member restrictions when filtering D‑Bus broadcast messages. As a result, a sandboxed Flatpak application can intercept broadcast signals on the D‑Bus session and AT‑SPI buses that are intended to be private, potentially exposing sensitive information to unauthorized applications. The flaw is an access‑control weakness, classified as CWE‑284. The impact is primarily the disclosure of confidential data that should have been protected by the restrictions.

Affected Systems

Red Hat Enterprise Linux 9 and 10 systems running xdg‑dbus‑proxy versions 0.1.6 and 0.1.7 are susceptible to this flaw. All other versions are unaffected. Users running these specific package releases should consider the vulnerability

Risk and Exploitability

The vulnerability has a CVSS score of 3.2, indicating low severity, and an EPSS score of < 1%, indicating a very low but nonzero exploitation probability. It is not listed in CISA KEV. The attack is likely to be carried out locally by a compromised or malicious Flatpak application that has access to the session bus. Because the vulnerability allows privileged signal interception without additional privileges, it can be leveraged by any user running a compromised or misbehaving sandboxed app, but it does not provide system‑wide escalation or remote code execution. Accordingly, the risk is low‑to‑moderate and mitigation is recommended promptly.

Generated by OpenCVE AI on September 19, 2026 at 19:10 UTC.

Remediation

Vendor Workaround

Affects versions 0.1.6 and 0.1.7. Fixed in 0.1.8.


OpenCVE Recommended Actions

  • Upgrade xdg-dbus-proxy to 0.1.8 or later on all Red Hat Enterprise Linux 9 and 10 hosts. This official fix restores proper filtering of broadcast messages for path, interface, and member restrictions.
  • Restart the Flatpak runtime or systemd‑user services after updating the package to ensure the new version is in use.
  • If upgrading immediately is not possible, restrict the Flatpak runtime’s access to the D‑Bus session bus by configuring its sandbox profile to limit broadcast signals.

Generated by OpenCVE AI on September 19, 2026 at 19:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
References

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bus that should be restricted, potentially exposing sensitive information to unauthorized applications.
Title Xdg-dbus-proxy: xdg-dbus-proxy: filtering for broadcast messages bypasses path/interface/member checks
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-284
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 3.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-22T23:07:03.845Z

Reserved: 2026-09-18T13:51:38.463Z

Link: CVE-2026-93676

cve-icon Vulnrichment

Updated: 2026-09-22T23:07:03.845Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T15:17:22.813

Modified: 2026-09-22T23:17:08.413

Link: CVE-2026-93676

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:25:26Z

Weaknesses