CVE-2026-97023
Received Received - Intake

Path Traversal in Flatpak During App Deployment

Vulnerability report for CVE-2026-97023, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: redhat-SADP

Description

A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside the deployment directory when the app is installed or upgraded. In system-wide installations, the deletion is performed as root.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
flatpak flatpak *
flatpak flatpak to 1.18.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-61 The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-97023 is a path traversal vulnerability in Flatpak, a Linux app sandboxing tool. It allows a malicious Flatpak app to delete files outside its deployment directory during installation or upgrade by exploiting the export/bin path. If installed system-wide, deletions occur with root privileges.

Detection Guidance

Detecting this vulnerability requires checking the installed Flatpak version and reviewing app installations. Run 'flatpak --version' to verify if your version is below 1.18.4. Inspect installed apps with 'flatpak list' and check for untrusted sources. No direct commands detect exploitation, but monitoring file deletions and reviewing app permissions may help.

Impact Analysis

This vulnerability can lead to arbitrary file deletion on your system. If you install untrusted Flatpak apps, especially system-wide, an attacker could delete critical files, disrupting system operations or causing data loss. The impact is higher for system-wide installations due to root privileges.

Compliance Impact

This vulnerability could violate compliance requirements like GDPR or HIPAA by enabling unauthorized file deletion or access, potentially compromising data integrity and availability. System-wide exploitation may lead to broader security incidents, requiring incident response and reporting under these regulations.

Mitigation Strategies

Immediately update Flatpak to version 1.18.4 or later. Avoid installing Flatpak apps from untrusted sources, especially system-wide. If updating is not possible, refrain from installing or upgrading Flatpak apps until patched. Review installed apps and remove any suspicious ones.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97023. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart