File System Vulnerability in Flatpak Affects User Cache Permissions
CVE-2026-97026
3.9LOW
What is CVE-2026-97026?
Flatpak has a vulnerability that allows the creation of temporary child repository directories in the user cache with world-writable permissions (0777). This configuration poses a risk on multi-user systems where a permissive umask is set, enabling other local users to potentially read or alter the contents of these directories during application or runtime installations. Such unauthorized access could lead to installation failures, as any tampered content would not pass signature or digest verification, effectively treating it as untrusted.
References
CVSS V3.1
Score:
3.9
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank AISLE for reporting this issue.