High severity8.8NVD Advisory· Published Jul 16, 2026· Updated Aug 26, 2026
CVE-2026-5674
CVE-2026-5674
Description
A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13- osv-coords12 versionspkg:rpm/almalinux/pipewire-jack-audio-connection-kit-develpkg:rpm/almalinux/pipewire-libspkg:rpm/almalinux/pipewire-module-x11pkg:rpm/almalinux/pipewire-pulseaudiopkg:rpm/almalinux/pipewirepkg:rpm/almalinux/pipewire-alsapkg:rpm/almalinux/pipewire-jack-audio-connection-kit-libspkg:rpm/almalinux/pipewire-develpkg:rpm/almalinux/pipewire-gstreamerpkg:rpm/almalinux/pipewire-jack-audio-connection-kitpkg:rpm/almalinux/pipewire-utilspkg:rpm/almalinux/pipewire-plugin-libcamera
< 1.4.11-1.el9_8+ 11 more
- (no CPE)range: < 1.4.11-1.el9_8
- (no CPE)range: < 1.4.11-1.el9_8
- (no CPE)range: < 1.4.11-1.el9_8
- (no CPE)range: < 1.4.11-1.el9_8
- (no CPE)range: < 1.4.11-1.el9_8
- (no CPE)range: < 1.4.11-1.el9_8
- (no CPE)range: < 1.4.11-1.el9_8
- (no CPE)range: < 1.4.11-1.el9_8
- (no CPE)range: < 1.4.11-1.el9_8
- (no CPE)range: < 1.4.11-1.el9_8
- (no CPE)range: < 1.4.11-1.el9_8
- (no CPE)range: < 1.4.11-1.el10_2
Patches
Vulnerability mechanics
References
7News mentions
1- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS HijacksThe Hacker News · Aug 3, 2026