THREAT OPS › Threat News › [NVD] CVE-2026-58015 (MEDIUM 5.9) — A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences,
[NVD] CVE-2026-58015 (MEDIUM 5.9) — A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences,
CVE-2026-58015 CVSS: 5.9 MEDIUM Published: 2026-06-30T13:19:17.707
A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exf
Indicators of compromise
- CVE-2026-58015cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-58015