File Read Vulnerability in Flatpak System Helper by Red Hat
CVE-2026-96284
2.5LOW
What is CVE-2026-96284?
A vulnerability in the Flatpak system helper allows a malicious user to gain read-access to files if a system OCI repository is configured. The issue arises when the OCI code paths in the system helper follow symlinks during the import of OCI images that are under the user's control. This behavior could lead to unauthorized access to sensitive information, highlighting the importance of proper configuration and security practices when using Flatpak.
References
CVSS V3.1
Score:
2.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Upstream acknowledges Simon McVittie as the original reporter.