Improper Authorization in fwupd - #VU140591

 

Improper Authorization in fwupd - #VU140591

Published: July 26, 2026 / Updated: July 31, 2026


Vulnerability identifier: #VU140591
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: N/A
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
fwupd

Detailed vulnerability description

The vulnerability allows a remote user to retarget a signed payload to a sibling device.

The vulnerability exists due to improper access control in the D-Bus install path when consuming unsigned routing metadata before trusted metadata validation. A remote user can submit a crafted archive with modified GUID or protocol fields to retarget a signed payload to a sibling device.

The demonstrated impact was limited to an emulator sibling module, and the advisory does not claim that every real hardware plugin accepts the payload.


Remediation

Install security update from vendor's website.

Sources