Improper access control in fwupd - #VU140590
Published: July 26, 2026 / Updated: July 31, 2026
fwupd
Detailed vulnerability description
The vulnerability allows a remote user to mutate live device state and block a later legitimate update.
The vulnerability exists due to improper state management in the D-Bus install path when processing an unsigned archive before polkit authorization and trust validation. A remote user can submit a crafted archive to mutate live device state and block a later legitimate update.
Scope is limited to affected MD_SET_* device classes and unconditionally copied fields. The rejecting install attempt can occur without a polkit call.