CVE-2026-59678
Last modified
CVE-2026-59678 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux-Gaming | PortProtonQt | < 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-59678?
How severe is CVE-2026-59678?
How do I fix CVE-2026-59678?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5966ThreatSonar Anti-Ransomware developed by TeamT5 has an Arbit…8.1
- CVE-2026-5967ThreatSonar Anti-Ransomware developed by TeamT5 has an Privi…8.8
- CVE-2026-59674A UNIX Symbolic Link (Symlink) Following vulnerability in op…7.1
- CVE-2026-59675When API audit logging is enabled, the middleware reads the …7.5
- CVE-2026-59676A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerab…5.8
- CVE-2026-59677A Missing Authorization vulnerability in selinux policycoreu…6.8
- CVE-2026-59679fs_read_glyphs() in the libXfont2 font-server client (src/fc…9
- CVE-2026-5968Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-59680An OS command injection vulnerability was found in yast2-use…8
- CVE-2026-59681A OS command injection vulnerability in yast2-auth-client al…8.8
- CVE-2026-59682Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB…9.1
- CVE-2026-59683The OpenRGB network protocol allows to write attacker contro…9.8
Are you affected by CVE-2026-59678?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
