Security Advisory

CVE-2026-5674

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-16 13:26:44
Last updated 2026-07-16 14:03:16
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.