CVE-2026-58015: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GNOME GLib
A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.
AI Analysis
Technical Summary
A vulnerability in GLib's D-Bus client-side DBUS_COOKIE_SHA1 SASL authentication mechanism allows a malicious D-Bus server to provide a cookie_context parameter with path traversal sequences. This improper validation leads to a path traversal attack (CWE-22), enabling the client to read arbitrary files on the filesystem. Successful exploitation requires the attacker to be in a position to perform a man-in-the-middle attack or control a malicious server that the client connects to. Additionally, data exfiltration requires an oracle attack involving guessing and hashing file contents. The vulnerability can lead to disclosure of sensitive information such as SSH keys and API tokens. Red Hat classifies this as a moderate severity issue with a CVSS v3.1 score of 5.9 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N). Red Hat advises connecting only to trusted D-Bus servers, using secure isolated networks, and disabling DBUS_COOKIE_SHA1 authentication to mitigate the risk. Security updates have been released for affected packages in Red Hat Enterprise Linux 8 and related products.
Potential Impact
The vulnerability allows an attacker who can perform a man-in-the-middle attack or operate a malicious D-Bus server to cause the client to read arbitrary files via path traversal sequences in the cookie_context parameter. This can lead to exfiltration of sensitive data such as SSH keys and API tokens from the filesystem. The attack complexity is high due to the need for an oracle attack involving guessing and hashing file contents. There is no impact on integrity or availability, but confidentiality is significantly affected.
Mitigation Recommendations
Red Hat recommends ensuring that applications connect only to trusted D-Bus servers and operate within secure, isolated networks to prevent man-in-the-middle attacks. Additionally, configuring the D-Bus connection to strictly require the EXTERNAL authentication mechanism and disabling DBUS_COOKIE_SHA1 authentication will completely mitigate this vulnerability. Security updates addressing this issue have been released for affected Red Hat Enterprise Linux 8 packages and should be applied promptly. Patch status is confirmed as fixed in updated packages provided by Red Hat.
CVE-2026-58015: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GNOME GLib
Description
A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.
CVSS v3.1
Score 5.9medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A vulnerability in GLib's D-Bus client-side DBUS_COOKIE_SHA1 SASL authentication mechanism allows a malicious D-Bus server to provide a cookie_context parameter with path traversal sequences. This improper validation leads to a path traversal attack (CWE-22), enabling the client to read arbitrary files on the filesystem. Successful exploitation requires the attacker to be in a position to perform a man-in-the-middle attack or control a malicious server that the client connects to. Additionally, data exfiltration requires an oracle attack involving guessing and hashing file contents. The vulnerability can lead to disclosure of sensitive information such as SSH keys and API tokens. Red Hat classifies this as a moderate severity issue with a CVSS v3.1 score of 5.9 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N). Red Hat advises connecting only to trusted D-Bus servers, using secure isolated networks, and disabling DBUS_COOKIE_SHA1 authentication to mitigate the risk. Security updates have been released for affected packages in Red Hat Enterprise Linux 8 and related products.
Potential Impact
The vulnerability allows an attacker who can perform a man-in-the-middle attack or operate a malicious D-Bus server to cause the client to read arbitrary files via path traversal sequences in the cookie_context parameter. This can lead to exfiltration of sensitive data such as SSH keys and API tokens from the filesystem. The attack complexity is high due to the need for an oracle attack involving guessing and hashing file contents. There is no impact on integrity or availability, but confidentiality is significantly affected.
Mitigation Recommendations
Red Hat recommends ensuring that applications connect only to trusted D-Bus servers and operate within secure, isolated networks to prevent man-in-the-middle attacks. Additionally, configuring the D-Bus connection to strictly require the EXTERNAL authentication mechanism and disabling DBUS_COOKIE_SHA1 authentication will completely mitigate this vulnerability. Security updates addressing this issue have been released for affected Red Hat Enterprise Linux 8 packages and should be applied promptly. Patch status is confirmed as fixed in updated packages provided by Red Hat.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-06-26T20:59:47.856Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-58015","vendor":"Red Hat"}]
Threat ID: 6a43c34927e9c79719d5bd6a
Added to database: 06/30/2026, 13:23:21 UTC
Last enriched: 08/03/2026, 19:48:41 UTC
Last updated: 08/14/2026, 00:41:13 UTC
Views: 137
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.