Symlink Vulnerability in Flatpak Affects Multiple Applications
CVE-2026-96807

4MEDIUM

Key Information:

Vendor

Flatpak

Status
Vendor
CVE Published:
23 September 2026

What is CVE-2026-96807?

Before version 1.18.1, a vulnerability in Flatpak allows a malicious sandboxed application to create a symbolic link that replaces a critical file, ~/.var/app/$appid/.ld.so. This can result in the regeneration of the linker cache at an unintended location. While the filenames and content produced are not controlled by the attacker, the potential risk remains significant, allowing for unintended file writes.

Affected Version(s)

Flatpak Linux 0 < 1.18.1

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.