CVE-2026-5674 Details
Description
A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.
A vulnerability in PipeWire, a multimedia server, allows attackers to escape sandboxed applications like Flatpak by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions in a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potentially compromising the user's system. This issue affects PipeWire versions through 1.0.5.
To mitigate this vulnerability, do not install Flatpaks with audio access or allow sandboxed processes to connect to the PulseAudio socket. Additionally, configure PipeWire to disable module loading and restrict the paths from which libraries can be loaded by certain PipeWire modules.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-427 | Uncontrolled Search Path Element | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 26, 2026 | CVE Modified | [email protected] |
| Aug 18, 2026 | CVE Modified | [email protected] |
| Aug 18, 2026 | CVE Modified | [email protected] |
| Aug 6, 2026 | CVE Modified | [email protected] |
| Aug 3, 2026 | CVE Modified | [email protected] |
| Jul 28, 2026 | CVE Modified | [email protected] |
| Jul 16, 2026 | CVE Modified | CISA-ADP |
| Jul 16, 2026 | New CVE Received | [email protected] |