CVE-2026-96284 - Flatpak: flatpak: arbitrary read-access to files in the system-helper context via oci symlink following
CVE ID :CVE-2026-96284
Published : Sept. 27, 2026, 10:04 p.m. | 1 hour, 7 minutes ago
Description :A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the system helper follow symlinks when importing OCI images that are under the user's control.
Severity: 2.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 27, 2026, 10:04 p.m. | 1 hour, 7 minutes ago
Description :A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the system helper follow symlinks when importing OCI images that are under the user's control.
Severity: 2.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...