Improper access control in Flatpak - #VU141399

 

Improper access control in Flatpak - #VU141399

Published: August 11, 2026


Vulnerability identifier: #VU141399
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass anti-downgrade checks and downgrade system apps or runtimes.

The vulnerability exists due to improper access control in the system helper RemoveLocalRef method when removing the remote ref of an app or runtime. A local user can remove the remote ref to bypass anti-downgrade checks and downgrade system apps or runtimes.

On a multi-user system, exploitation requires an active local login session and can expose other users of the same system to an older app version with unfixed vulnerabilities.


Affected software

Flatpak

Remediation

Install security update from vendor's website.

Flatpak - update to 1.18.1

External References

Related Security Bulletins