CVE-2026-96283
Received Received - Intake

Flatpak SystemHelper Unauthorized Pull Cancellation Flaw

Vulnerability report for CVE-2026-96283, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: redhat-SADP

Description

By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to stop it. Ongoing pulls cannot be stopped.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
freedesktop flatpak *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an attacker to call a specific Flatpak function on another user's system, which removes the tracking of an ongoing download without actually stopping it. This makes it impossible for the legitimate user to cancel the download.

Detection Guidance

This vulnerability cannot be directly detected through standard commands as it involves a logic flaw in Flatpak's internal tracking. Monitor for unexpected high network or disk usage from Flatpak processes, especially if pulls are not properly canceling. Check Flatpak logs for unusual behavior in system helper operations.

Impact Analysis

If exploited, this could allow an attacker to consume system resources by preventing legitimate users from stopping unwanted downloads. It may also lead to denial-of-service conditions if downloads consume excessive bandwidth or disk space.

Compliance Impact

This vulnerability does not directly impact compliance with standards like GDPR or HIPAA as it involves a local privilege escalation issue in Flatpak, affecting internal tracking of pull operations rather than data protection or privacy controls.

Mitigation Strategies

No specific mitigation steps are provided in the given context. Monitor Flatpak updates and apply patches once available. Avoid allowing untrusted users to interact with Flatpak operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-96283. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart