OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-96275

HIGH · CVSS 8.8 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

A vulnerability exists in Flatpak that allows a malicious or compromised repository to write attacker-controlled content to arbitrary locations on the host filesystem, potentially with root privileges on system installations. This is due to improper handling of symlinks and insufficient sanitization of blob names, which can lead to directory traversal attacks. Organizations using Flatpak should prioritize addressing this issue to mitigate the risk of unauthorized file access and system compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-96275
Severity
HIGH
CVSS
8.8
EPSS
0.36%

Original NVD Description

A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal.