CVE-2026-59678 Details
Description
An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe.
A vulnerability in Linux Gaming PortProtonQt prior to version 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe allows users to improperly manage filesystem mounts and unmounts, as well as alter network settings through NetworkManager. This issue arises from Polkit rules that incorrectly authorize these actions based on command line arguments, potentially enabling any user to perform them.
Users can update to PortProtonQt version 1.3.1, which includes a fix for the Polkit rules, ensuring that these actions are only available to users in an active local session and members of the portprotonqt group.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 23, 2026CISA-ADP
Assessed Jul 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-59678 | [email protected] | Issue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Linux-Gaming PortProtonQt | < 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe |
CPE
Remediation
| |
| openSUSE Tumbleweed | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Modified | CISA-ADP |
| Jul 23, 2026 | New CVE Received | [email protected] |
Volerion