CVE-2026-5674 is a high-severity vulnerability in PipeWire, a multimedia server, involving its PulseAudio compatibility layer. The flaw allows a sandboxed application environment, including Flatpak-style sandboxes, to influence library loading in a way that results in uncontrolled search path behavior. An attacker operating with minimal privileges inside the sandbox can cause a malicious library to be loaded, leading to execution of attacker-controlled code outside the intended sandbox boundary. The issue is classified as CWE-427 and represents a sandbox escape that can transition a low-privileged in-sandbox foothold into code execution in the broader user context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A PipeWire sandbox escape / user-context code execution issue in the PulseAudio compatibility layer caused by a chain of flaws: authentication cookie not validated, module loading enabled by default, and arbitrary library loading via dlopen() without path validation.
A sandbox escape and arbitrary code execution vulnerability in PipeWire caused by malicious library loading via the PulseAudio compatibility layer.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.