Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34080

23
FAUCET Score

OVERVIEW CVE-2026-34080 is a policy parser vulnerability in xdg-dbus-proxy versions prior to 0.1.7 that allows unauthorized access to D-Bus messages. The vulnerability stems from improper handling of eavesdrop policy rules, specifically when whitespace appears before the equals sign (e.g., eavesdrop ='true'). This parsing failure enables clients to bypass eavesdrop restrictions and intercept D-Bus communications they are not authorized to access. The issue affects xdg-dbus-proxy, a filtering proxy used to control D-Bus connections, and is resolved in version 0.1.7 and later. SEVERITY The vulnerability carries a CVSS score of 5.5 (Medium) with a local attack vector, low complexity, and low privilege requirements. No user interaction is necessary for exploitation. The impact is limited to confidentiality, with affected systems experiencing unauthorized disclosure of D-Bus message content. The FAUCET Risk Score of 41.0 reflects moderate concern, and the EPSS score of 0.000080000 indicates this vulnerability is not widely exploited relative to the broader CVE landscape. EXPLOITATION STATUS There is no evidence of active exploitation. The vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and is inactive on threat intelligence hot lists. No public exploit code appears readily available. Community attention remains minimal, suggesting organizations have sufficient time to patch before widespread adoption of exploitation techniques.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.1.7CPE matchmatch criteria
cpe:2.3:a:flatpak:xdg-dbus-proxy:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

6.8MEDIUM

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
7.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0018 is in the 39th percentile among its peer group of 15,938 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

ubuntupatch availablevia ubuntu_usn
Product: xdg-dbus-proxy (focal)Fixed in: 0.1.2-1ubuntu0.1~esm1
ubuntupatch availablevia ubuntu_usn
Product: xdg-dbus-proxy (jammy)Fixed in: 0.1.3-1ubuntu0.1
ubuntupatch availablevia ubuntu_usn
Product: xdg-dbus-proxy (noble)Fixed in: 0.1.5-1ubuntu0.2
ubuntupatch availablevia ubuntu_usn
Product: xdg-dbus-proxy (questing)Fixed in: 0.1.6-1ubuntu0.1
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (2)

ubuntuUSN-8167-2

xdg-dbus-proxy vulnerability

May 26, 2026
ubuntuUSN-8167-1

xdg-dbus-proxy vulnerability

Apr 13, 2026

References

lists.debian.org / debian-lts-announce/2026/04/msg00022.html
openwall.com / lists/oss-security/2026/04/10/15
Third Party Advisory
github.com / flatpak/xdg-dbus-proxy/security/advisories/GHSA-vjp5-hjfm-7677
Vendor Advisory