Improper Authorization in fwupd - #VU140591
Published: July 26, 2026 / Updated: July 31, 2026
fwupd
Detailed vulnerability description
The vulnerability allows a remote user to retarget a signed payload to a sibling device.
The vulnerability exists due to improper access control in the D-Bus install path when consuming unsigned routing metadata before trusted metadata validation. A remote user can submit a crafted archive with modified GUID or protocol fields to retarget a signed payload to a sibling device.
The demonstrated impact was limited to an emulator sibling module, and the advisory does not claim that every real hardware plugin accepts the payload.