SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-5674

HIGH · CVSS 8.8 EPSS 0.13% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A vulnerability in PipeWire's PulseAudio compatibility layer allows attackers to escape from sandboxed applications like Flatpak, enabling them to execute arbitrary code outside the sandbox. This poses a significant risk as it can lead to full system compromise for users running affected applications. Organizations utilizing PipeWire in their multimedia environments should prioritize addressing this issue to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-5674
Severity
HIGH
CVSS
8.8
EPSS
0.13%

Original NVD Description

A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.