CVE-2026-97025
Received Received - Intake

Flatpak OCI Token Exposure via World-Readable Cache Permissions

Vulnerability report for CVE-2026-97025, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: redhat-SADP

Description

Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cache directory, allowing other local users on a multi-user system to read the token and impersonate the authenticated user against the OCI repository. Only OCI-based sources (e.g. as used by Fedora) are affected; libostree-based sources such as Flathub are not.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
flatpak flatpak *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-378 Opening temporary files without appropriate measures or controls can leave the file, its contents and any function that it impacts vulnerable to attack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Flatpak stores OCI repository authentication tokens with overly permissive file permissions (0644) in the system-helper's cache directory. This allows any local user on a multi-user system to read the token and impersonate the authenticated user when accessing the OCI repository.

Detection Guidance

Check for world-readable OCI authentication tokens in the system-helper's cache directory, typically located at /var/lib/flatpak/cache/oci-auth-token. Use the command: ls -l /var/lib/flatpak/cache/oci-auth-token to verify permissions. If the file has 0644 permissions, it is vulnerable.

Impact Analysis

On a multi-user system, other local users could access your OCI repository token and impersonate you. This could lead to unauthorized access to private repositories or actions performed under your identity.

Compliance Impact

This vulnerability could violate data protection requirements by allowing unauthorized access to sensitive repository data. It may lead to breaches of confidentiality obligations under GDPR or HIPAA if repository contents include protected health or personal information.

Mitigation Strategies

Change the permissions of the OCI authentication token file to 0600 using chmod 0600 /var/lib/flatpak/cache/oci-auth-token. Ensure no other users can read the file. Monitor for unauthorized access or token misuse.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97025. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart