CVE-2026-97026
Received Received - Intake

Flatpak Temporary Repository Directory Permission Vulnerability

Vulnerability report for CVE-2026-97026, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: redhat-SADP

Description

Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems with a permissive umask, other local users could read or modify the temporary directory used while installing apps or runtimes, potentially causing installation failures (denial of service); tampered content would fail signature/digest verification rather than being trusted.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-378 Opening temporary files without appropriate measures or controls can leave the file, its contents and any function that it impacts vulnerable to attack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). This allows other local users on multi-user systems with a permissive umask to read or modify these directories while installing apps or runtimes.

Detection Guidance

Check for world-writable temporary directories under the user cache (typically ~/.cache/flatpak). Use commands like 'find ~/.cache/flatpak -type d -perm 0777' to identify them.

Impact Analysis

On affected systems, other local users could cause installation failures by tampering with temporary directories. Tampered content would fail signature verification instead of being trusted, leading to potential denial of service or corrupted installations.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized local users to read or modify temporary repository directories during app or runtime installations. This may lead to data exposure or integrity issues, violating confidentiality and availability requirements under these regulations.

Mitigation Strategies

Set a restrictive umask (e.g., 0027) to prevent world-writable permissions. Temporarily remove write permissions from the cache directory with 'chmod 750 ~/.cache/flatpak' until a patch is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97026. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart