Flatpak App Vulnerability on Multi-User Systems by Red Hat
CVE-2026-96281

Currently unrated

What is CVE-2026-96281?

On systems utilizing Flatpak in a multi-user environment, a local user with an active session can downgrade a Flatpak application to a previous version by manipulating application references. This action bypasses the safeguards typically designed to prevent the rollback to outdated versions, potentially reintroducing known vulnerabilities. A malicious local user may exploit this behavior, thereby compromising the application’s integrity for other users sharing the same system, increasing the risk of security breaches across the platform.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Upstream acknowledges Vivek Parikh (BreachX Zero Day Labs) as the original reporter.
.