#VU125296 Improper access control in Flatpak - CVE-2026-34078
Published: April 8, 2026
Flatpak
Flatpak
Description
The vulnerability allows a remote attacker to execute code in the host context.
The vulnerability exists due to improper access control in the Flatpak portal and flatpak run when processing sandbox-expose options containing app-controlled symlinks. A remote attacker can supply a crafted path to gain access to arbitrary host files and execute code in the host context.
The issue enables sandbox escape from a Flatpak app to the host environment.