Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 26 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 25 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lxqt
Lxqt pcmanfm-qt |
|
| Vendors & Products |
Lxqt
Lxqt pcmanfm-qt |
Fri, 22 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Privilege Escalation via D‑Bus ShowFolders Call in PCManFM-Qt |
Fri, 22 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 22 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI in an org.freedesktop.FileManager1.ShowFolders D-Bus method call, PCManFM-Qt delegates to a different program (based on the file type) without user confirmation. This could be used to achieve code execution or circumvent network namespace restrictions. NOTE: those outcomes are potentially unwanted by most users; however, the behavior of the product does comply with the applicable specification, and a simplistic solution (ensuring that the URI does not name a regular file) may have adverse consequences for I/O. | |
| Weaknesses | CWE-913 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-24T19:30:09.123Z
Reserved: 2026-05-22T18:43:05.097Z
Link: CVE-2026-48700
Updated: 2026-05-24T19:30:09.123Z
Status : Deferred
Published: 2026-05-22T19:17:04.623
Modified: 2026-06-17T10:55:13.093
Link: CVE-2026-48700
No data.
OpenCVE Enrichment
Updated: 2026-05-25T11:33:51Z