CVE-2026-4948

⚪ Do wiadomości

Błąd w firewalld pozwala lokalnemu użytkownikowi na nieautoryzowane zmiany w konfiguracji zapory.

CVSS
5.5
EPSS
0.1%
Exploit
none
Vendor
firewalld
Opis źródłowy (NVD)

A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime firewall state without proper authentication, leading to unauthorized changes in network security configurations.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.1%
Opublikowano (NVD)2026-03-27 06:16:39 UTC
Ostatnia modyfikacja (NVD)2026-09-16 00:17:04 UTC
Referencje