A security disclosure revealed that PortProtonQt shipped an insecure custom Polkit rule that allowed local users to bypass authorization checks and gain elevated access to NetworkManager and UDisks2 actions. The rule relied on inspecting a process command line with ps to identify the ppqtos program, enabling attackers to spoof or race the check and then modify system network connections or mount and unmount file systems without proper authorization. The issue affects PortProtonQt 1.3.0 and was reportedly present since 0.1.12.
Upstream fixed the flaw in PortProtonQt 1.3.1, replacing the weak authorization logic so only users in an active local session and a dedicated portprotonqt group can use the additional Polkit actions. The vulnerability was disclosed as CVE-2026-59678, although one advisory also referenced CVE-2026-59676; reporting indicates the practical impact is unauthorized changes to networking and storage state, leading primarily to denial of service and system integrity degradation rather than a confirmed full root compromise.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-22, a public security report disclosed the PortProtonQt local privilege escalation and authentication bypass issue and stated that CVE-2026-59678 had been assigned. One source notes a conflicting mention of CVE-2026-59676 in the report text, but the timeline identifies CVE-2026-59678 as the assigned identifier.
Upstream fixed the vulnerable authorization logic in PortProtonQt 1.3.1, including commit f0ab40a2d, by restricting the extra Polkit actions to users in an active local session who belong to a dedicated portprotonqt group.
The insecure custom Polkit rule that trusted process command-line inspection was reportedly introduced in PortProtonQt version 0.1.12, enabling local users to spoof authorization checks for NetworkManager and UDisks2 actions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcesecurity.opensuse.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.