
CVE-2026-48700: PCManFM-Qt: When a regular file's path is passed as a URI in an org.freedesktop.FileManager1.ShowFolders D-Bus method call, PCManFM-Qt delegates to a different program (based on the file type) without user confirmation https://www.openwall.com/lists/oss-security/2026/05/24/6
Post summary
PCManFM-Qt allows a file path passed via a D-Bus ShowFolders call to delegate to another program without user confirmation, marking it as a newly disclosed vulnerability. No PoC, exploit, patch, or active exploitation evidence is referenced.



