OVERVIEW CVE-2026-34080 is a policy parser vulnerability in xdg-dbus-proxy versions prior to 0.1.7 that allows unauthorized access to D-Bus messages. The vulnerability stems from improper handling of eavesdrop policy rules, specifically when whitespace appears before the equals sign (e.g., eavesdrop ='true'). This parsing failure enables clients to bypass eavesdrop restrictions and intercept D-Bus communications they are not authorized to access. The issue affects xdg-dbus-proxy, a filtering proxy used to control D-Bus connections, and is resolved in version 0.1.7 and later. SEVERITY The vulnerability carries a CVSS score of 5.5 (Medium) with a local attack vector, low complexity, and low privilege requirements. No user interaction is necessary for exploitation. The impact is limited to confidentiality, with affected systems experiencing unauthorized disclosure of D-Bus message content. The FAUCET Risk Score of 41.0 reflects moderate concern, and the EPSS score of 0.000080000 indicates this vulnerability is not widely exploited relative to the broader CVE landscape. EXPLOITATION STATUS There is no evidence of active exploitation. The vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and is inactive on threat intelligence hot lists. No public exploit code appears readily available. Community attention remains minimal, suggesting organizations have sufficient time to patch before widespread adoption of exploitation techniques.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.1.7CPE matchmatch criteria | cpe:2.3:a:flatpak:xdg-dbus-proxy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.