Improper Authorization in fwupd - #VU140589
Published: July 26, 2026 / Updated: July 31, 2026
fwupd
Detailed vulnerability description
The vulnerability allows a remote user to install a downgrade as a trusted update without a prompt.
The vulnerability exists due to improper access control in the D-Bus install path when consuming unsigned metainfo before trusted metadata validation. A remote user can submit a crafted archive with a modified release version field to install a downgrade as a trusted update without a prompt.
Exploitation requires an active seat session with the unmodified auto-launched daemon, upstream polkit policy, and OnlyTrusted enabled.