CVE-2026-97026

Public on 2026-09-28
Modified on 2026-10-01
Description
The child temporary directories allocated under the user cache (/var/tmp/flatpak-cache-*) are created with mode 0777. On multi-user systems this could allow other local users to modify the app as it is being installed.
https://github.com/flatpak/flatpak/security/advisories/GHSA-r9w3-qx54-qvc8
Severity
Low severity
Low
See what this means
CVSS v3 Base Score
3.3
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core flatpak Pending Fix
Amazon Linux 2023 flatpak Pending Fix
Amazon Linux 2027 Preview flatpak Pending Fix
Amazon Linux 2023 flatpak-builder Pending Fix
Amazon Linux 2027 Preview flatpak-builder Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 3.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:L