Improper access control in Flatpak - CVE-2026-96281

 

Improper access control in Flatpak - CVE-2026-96281

Published: August 11, 2026 / Updated: September 28, 2026


Vulnerability identifier: #VU141399
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-96281
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass anti-downgrade checks and downgrade system apps or runtimes.

The vulnerability exists due to improper access control in the system helper RemoveLocalRef method when removing the remote ref of an app or runtime. A local user can remove the remote ref to bypass anti-downgrade checks and downgrade system apps or runtimes.

On a multi-user system, exploitation requires an active local login session and can expose other users of the same system to an older app version with unfixed vulnerabilities.


Affected software

Flatpak

How to mitigate CVE-2026-96281

Install security update from vendor's website.

Flatpak - update to 1.18.1

External References

Related Security Bulletins