CVE-2026-96281
Received Received - Intake

Flatpak App Version Downgrade via Local Ref Removal

Vulnerability report for CVE-2026-96281, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: redhat-SADP

Description

On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the anti-downgrade check to fail to find a reference date. A malicious local user could use this to expose other users of the same system to an app version with unfixed vulnerabilities.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows a local user on a multi-user system to downgrade a system-wide Flatpak app to an older version by removing the app's remote reference. This bypasses the anti-downgrade check, which fails to find a reference date. The attacker could then expose other users to an outdated app version with unfixed vulnerabilities.

Detection Guidance

This vulnerability requires local access to exploit and involves downgrading Flatpak apps via the RemoveLocalRef method. Detection involves checking for unauthorized app version changes or removal of remote refs. Monitor Flatpak logs for suspicious RemoveLocalRef calls or version rollbacks. Check system logs for Flatpak operations by unprivileged users.

Impact Analysis

If you share a multi-user system, a malicious local user could downgrade a shared Flatpak app to an older, vulnerable version. This could expose you to security risks like exploits or data breaches if the older version has unpatched flaws.

Compliance Impact

This vulnerability allows a local user to downgrade a Flatpak app to an older version with unfixed vulnerabilities. This could expose other users on the same system to security risks, potentially violating compliance requirements for data protection and security in standards like GDPR and HIPAA, which mandate protection against known vulnerabilities and unauthorized access.

Mitigation Strategies

Update Flatpak to the latest version to ensure the anti-downgrade check is enforced. Restrict local user access to system-wide Flatpak operations to prevent unauthorized ref removal.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-96281. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart