CVE-2026-4948 Details
Description
A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime firewall state without proper authentication, leading to unauthorized changes in network security configurations.
A vulnerability exists in firewalld versions through 2.4.0, where local unprivileged users can exploit mis-authorized D-Bus setters, setZoneSettings2 and setPolicySettings. This flaw allows users to alter the runtime firewall state without proper authentication, leading to unauthorized changes in network security configurations. The issue arises when the firewalld desktop policy is active, enabling local users to modify firewall settings via the mis-authorized D-Bus interfaces.
To address this vulnerability, deactivate the firewalld desktop policy on systems where local unprivileged user access poses a risk. If firewalld is not needed, it can be disabled, though this may affect network services that rely on it. To disable firewalld, use the commands 'sudo systemctl stop firewalld' followed by 'sudo systemctl disable firewalld'. A system restart or service reload may be necessary for the changes to take effect.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-279 | Incorrect Execution-Assigned Permissions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| firewalld firewalld | <= 2.4.0 |
CPE
Remediation
| |
| redhat enterprise linux | 7.0 |
CPE
Remediation
| |
Change History
13 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 16, 2026 | CVE Modified | [email protected] |
| Sep 16, 2026 | CVE Modified | [email protected] |
| Sep 1, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | CVE |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 21, 2026 | CVE Modified | [email protected] |
| Jul 30, 2026 | CVE Modified | [email protected] |
| Jul 28, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 15, 2026 | CVE Modified | CVE |
| Apr 30, 2026 | Initial Analysis | [email protected] |
| Mar 27, 2026 | New CVE Received | [email protected] |