Security Advisory

CVE-2026-93676

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-18 14:19:34
Last updated 2026-09-18 15:10:34
Assigner redhat
CVSS score 3.2
State PUBLISHED

Description

xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bus that should be restricted, potentially exposing sensitive information to unauthorized applications.