SB2026073115 - Multiple vulnerabilities in fwupd
Published: July 31, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) Improper Authorization (CVE-ID: N/A)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to install a downgrade as a trusted update without a prompt.
The vulnerability exists due to improper access control in the D-Bus install path when consuming unsigned metainfo before trusted metadata validation. A remote user can submit a crafted archive with a modified release version field to install a downgrade as a trusted update without a prompt.
Exploitation requires an active seat session with the unmodified auto-launched daemon, upstream polkit policy, and OnlyTrusted enabled.
2) Improper access control (CVE-ID: N/A)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to mutate live device state and block a later legitimate update.
The vulnerability exists due to improper state management in the D-Bus install path when processing an unsigned archive before polkit authorization and trust validation. A remote user can submit a crafted archive to mutate live device state and block a later legitimate update.
Scope is limited to affected MD_SET_* device classes and unconditionally copied fields. The rejecting install attempt can occur without a polkit call.
3) Improper Authorization (CVE-ID: N/A)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to retarget a signed payload to a sibling device.
The vulnerability exists due to improper access control in the D-Bus install path when consuming unsigned routing metadata before trusted metadata validation. A remote user can submit a crafted archive with modified GUID or protocol fields to retarget a signed payload to a sibling device.
The demonstrated impact was limited to an emulator sibling module, and the advisory does not claim that every real hardware plugin accepts the payload.
Remediation
Install update from vendor's website.