OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-94422

HIGH · CVSS 8.8 EPSS 0.69% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability in xdg-dbus-proxy versions prior to 0.1.9 allows attackers to bypass message filtering on the D-Bus session bus, enabling arbitrary code execution by malicious or compromised Flatpak applications outside their intended sandbox. This poses a significant risk to systems utilizing Flatpak or similar app frameworks like Firejail, making it crucial for developers and system administrators managing these environments to prioritize patching this issue. Immediate action is recommended to mitigate potential exploitation and safeguard application integrity.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-94422
Severity
HIGH
CVSS
8.8
EPSS
0.69%

Original NVD Description

An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, but it is released as a separate project and is sometimes used by other app frameworks such as Firejail.