Status: UPDATED
| Advisory ID: CVE-2026-94422
Key Details
| CVE | CVE-2026-94422 |
| CVSS Score / Version | 8.8 (High) / CVSS v3.1 |
| Updated | 2026-10-02 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Red Hat Red Hat Enterprise Linux 10, Red Hat Red Hat Enterprise Linux 9, and Fedora Fedora |
| Classified as | CWE-290 (Authentication Bypass by Spoofing) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, but it is released as a separate project and is sometimes used by other app frameworks such as Firejail. (NVD)
What to Do
Monitor Red Hat's and Fedora's web pages for any future patch releases.
References