Symlink Traversal Vulnerability in Flatpak from Activating Local User Sessions
CVE-2026-96808

7.4HIGH

Key Information:

Vendor

Flatpak

Status
Vendor
CVE Published:
23 September 2026

What is CVE-2026-96808?

The vulnerability in Flatpak's revokefs writer, prior to version 1.18.1, allowed local users to exploit symlink traversal issues. By leveraging this flaw, attackers could create a symlink in one revokefs session pointing to another session's directory. This granted them the ability to modify files across sessions, undermining the integrity of ostree commit objects in the system repository. Ultimately, this led to unauthorized file writes and could facilitate local root privilege escalation, posing significant risks to system security.

Affected Version(s)

Flatpak Linux 0 < 1.18.1

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.