Creation of Temporary File With Insecure Permissions in Flatpak - CVE-2026-97026
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to insecure temporary directory permissions in temporary child repositories under the system-helper cache path when installing apps. A local user can modify the temporary directory to cause a denial of service.
Exploitation is limited to multi-user systems where the user's umask permits other users to write to the cache directory.