Description
A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside the deployment directory when the app is installed or upgraded. In system-wide installations, the deletion is performed as root.
Published: 2026-09-28
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Root‑level arbitrary file deletion
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a path‑traversal flaw in Flatpak's handling of the export/bin directory during app deployment. A malicious Flatpak application can use the flaw to delete any file outside its deployment directory when the app is installed or upgraded. In system‑wide installations the deletion happens with root privileges, allowing the attacker to remove critical system files or user data, potentially disrupting services or facilitating further compromise. This flaw is identified as CWE‑61.

Affected Systems

The issue affects Red Hat Enterprise Linux releases 7, 8, 9, and 10 on which Flatpak is installed. No specific sub‑version is singled out, so all current versions of those RHEL releases that ship Flatpak are vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a high impact, and while the EPSS score is not available, the vulnerability is not listed in the CISA KEV catalog. Exploitation requires installing or upgrading a malicious Flatpak package, which means the attacker must first convince a user to add a non‑trusted app in a system‑wide deployment. If successful, the deletion is performed as root, giving the attacker the ability to destroy critical files. The risk is therefore significant for environments that use system‑wide Flatpak installations.

Generated by OpenCVE AI on September 28, 2026 at 20:25 UTC.

Remediation

Vendor Workaround

Avoid installing Flatpak apps from non-trusted publishers, particularly in system-wide deployments.


OpenCVE Recommended Actions

  • Restrict Flatpak to trusted repositories and avoid installing packages from untrusted publishers, especially for system‑wide deployments.
  • Disable or restrict the system‑wide Flatpak installation feature if it is not required, or configure it to run as an unprivileged user instead of root.
  • Monitor the Flatpak repository configuration and audit installed packages for unauthorized entries; remove any suspicious or untrusted applications.
  • Stay alert for an official patch from Red Hat or Flatpak maintainers and apply it immediately once available.

Generated by OpenCVE AI on September 28, 2026 at 20:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6524-1 flatpak security update
History

Mon, 28 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside the deployment directory when the app is installed or upgraded. In system-wide installations, the deletion is performed as root.
Title Flatpak: flatpak: arbitrary file deletion in root context via path traversal in deploy directory export/bin
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-61
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-28T19:27:14.558Z

Reserved: 2026-09-23T21:06:34.212Z

Link: CVE-2026-97023

cve-icon Vulnrichment

Updated: 2026-09-28T19:26:45.489Z

cve-icon NVD

Status : Received

Published: 2026-09-28T19:16:50.710

Modified: 2026-09-28T20:17:11.823

Link: CVE-2026-97023

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T20:30:06Z

Weaknesses
  • CWE-61

    UNIX Symbolic Link (Symlink) Following