{"id":"CVE-2026-96281","published":"2026-09-27T21:17:04.330","lastModified":"2026-09-29T21:29:07.663","description":"On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the anti-downgrade check to fail to find a reference date. A malicious local user could use this to expose other users of the same system to an app version with unfixed vulnerabilities.","cvssScore":6.2,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-284"],"vendors":[],"products":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-96281","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2539421","tags":[]},{"url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-q4gr-vc25-57m5","tags":[]}],"exploitRefs":[{"url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-q4gr-vc25-57m5","tags":[]}],"hasPoc":true,"ai":null}