Description
A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certain host system files (such as passwd, group, machine-id, or resolv.conf) to be emptied or replaced with a symlink when the app is installed or upgraded. In system-wide installations, the write is performed as root.
Published: 2026-09-29
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Privileged File Write
Action: Immediate Patch
AI Analysis

Impact

A malicious Flatpak application can exploit a path traversal flaw while deploying files in the /etc directory, causing critical host files such as /etc/passwd, /etc/group, /etc/machine-id, or /etc/resolv.conf to be emptied or replaced with a symbolic link. The vulnerability enables tampering with authentication, networking, or system identification, and is identified as a classic file‑system path traversal weakness (CWE‑61).

Affected Systems

Red Hat Red Enterprise Linux 7, 8, 9, and 10 are affected because Flatpak is bundled with these operating systems, and any system that performs system‑wide Flatpak installations runs with root privileges and is therefore at risk.

Risk and Exploitability

The CVSS score of 7.1 classifies the issue as high severity, and the EPSS score is not available, meaning no current exploitation probability is published. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. An attacker only needs to install or upgrade a malicious Flatpak package in a system‑wide context to trigger the privileged write, making it a straightforward local privilege escalation vector.

Generated by OpenCVE AI on September 29, 2026 at 04:50 UTC.

Remediation

Vendor Workaround

Avoid installing Flatpak apps from untrusted publishers, especially system-wide.


OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade Flatpak to a version that fixes the path traversal flaw
  • Avoid installing Flatpak applications from untrusted publishers, especially in system‑wide mode
  • Configure Flatpak to run only in user mode and restrict system‑wide installation privileges when possible

Generated by OpenCVE AI on September 29, 2026 at 04:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6524-1 flatpak security update
History

Tue, 29 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Description A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certain host system files (such as passwd, group, machine-id, or resolv.conf) to be emptied or replaced with a symlink when the app is installed or upgraded. In system-wide installations, the write is performed as root.
Title Flatpak: flatpak: arbitrary write in root context via path traversal in deploy directory files/etc
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-61
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-29T03:23:00.602Z

Reserved: 2026-09-23T21:09:09.344Z

Link: CVE-2026-97024

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T04:18:02.397

Modified: 2026-09-29T04:18:02.397

Link: CVE-2026-97024

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T05:00:07Z

Weaknesses
  • CWE-61

    UNIX Symbolic Link (Symlink) Following