Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-96281— Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system apps/runtimes

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在多用户系统中,具有活动本地登录会话的用户可以通过通过非特权系统助手(system-helper)调用 RemoveLocalRef 方法移除该应用的远程引用,从而将系统范围的 Flatpak 应用降级到较旧版本。这会导致反降级检查无法找到引用日期,从而失效。恶意本地用户可利用此漏洞使同一系统中的其他用户使用存在未修复漏洞的应用版本,从而带来安全风险。

CVSS 6.2 · Medium

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-96281

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system apps/runtimes
Source: CVE Program / CVE List V5
Vulnerability Description
On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the anti-downgrade check to fail to find a reference date. A malicious local user could use this to expose other users of the same system to an app version with unfixed vulnerabilities.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
访问控制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9

II. Public POCs for CVE-2026-96281

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-96281

请登录查看更多情报信息。

Other References for CVE-2026-96281 (3)

Same Patch Batch · Red Hat · 2026-09-27 · 6 CVEs total

CVE-2026-96280 7.5 HIGH Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit systems
CVE-2026-96279 6.5 MEDIUM Flatpak: flatpak: path traversal issue in oci archive extraction via hardlinks
CVE-2026-96283 3.3 LOW Flatpak: flatpak: flatpak-system-helper cross-user cancelpull orphans another user's ongoi
CVE-2026-96282 3.1 LOW Flatpak: flatpak: extension metadata path traversal file existence oracle
CVE-2026-96284 2.5 LOW Flatpak: flatpak: arbitrary read-access to files in the system-helper context via oci syml

IV. Related Vulnerabilities

V. Comments for CVE-2026-96281

No comments yet


Leave a comment