CVE-2026-59678
Received Received - Intake

Incorrect Authorization in PortProtonQt Allows Privilege Escalation

Vulnerability report for CVE-2026-59678, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-23

Last updated on: 2026-07-23

Assigner: SUSE

Description

An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-23
Last Modified
2026-07-23
Generated
2026-07-23
AI Q&A
2026-07-23
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Incorrect Authorization issue in Linux-Gaming PortProtonQt. It allows any local user to mount or unmount arbitrary file systems and modify network settings via NetworkManager without proper authentication. The flaw stems from insecure Polkit rules that grant permissions based on easily manipulated command-line checks.

Detection Guidance

Check if PortProtonQt is installed and review the Polkit rules file at /usr/share/polkit-1/rules.d/ru.linux_gaming.PortProtonQt.rules. Look for insecure rules that grant broad permissions without proper authentication. Commands like 'ls -l /usr/share/polkit-1/rules.d/ru.linux_gaming.PortProtonQt.rules' and 'cat /usr/share/polkit-1/rules.d/ru.linux_gaming.PortProtonQt.rules' can help inspect the file.

Impact Analysis

An attacker with local access could exploit this to alter system files, disrupt services, or change network configurations, potentially causing data loss or denial of service. The attack requires no special privileges beyond local system access.

Compliance Impact

This vulnerability could lead to unauthorized system modifications, violating integrity and confidentiality requirements in GDPR and HIPAA. Unrestricted file system access may expose sensitive data, while network changes could disrupt secure configurations.

Mitigation Strategies

Update PortProtonQt to the latest version (0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe or later). If updating is not possible, remove or restrict the insecure Polkit rules file. Ensure only trusted users in the portprotonqt group or active local sessions can perform privileged actions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59678. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart