CVE-2026-96284

EUVD-2026-88046
A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the system helper follow symlinks when importing OCI images that are under the user's control.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.5 LOW
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 2.97%
Debian logo
Debian Releases
Debian Product
Codename
flatpak
bookworm
1.14.10-1~deb12u2
fixed
bookworm (security)
1.14.10-1~deb12u2
fixed
forky
1.18.2-1
fixed
sid
1.18.3-1
fixed
trixie
1.16.6-1~deb13u2
fixed
trixie (security)
1.16.6-1~deb13u2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
flatpak
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
not-affected