Arbitrary File Disclosure Vulnerability in Flatpak Applications by Red Hat
CVE-2026-96279

6.5MEDIUM

What is CVE-2026-96279?

A vulnerability exists within Flatpak applications where a malicious OCI registry can create hard links to arbitrary host files during the installation or update process. This could allow unauthorized disclosure of sensitive information contained in files on the host system. For instance, if a system-wide installation is done with root privileges, it may expose critical files such as /etc/shadow, which holds hashed passwords for user accounts. This flaw underscores the necessity for stringent security measures and validation of remote sources when managing application installations.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Upstream acknowledges Sebastian Wick as the original reporter.
.