{"id":"CVE-2026-97026","published":"2026-09-28T21:17:19.907","lastModified":"2026-09-29T21:29:07.663","description":"Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems with a permissive umask, other local users could read or modify the temporary directory used while installing apps or runtimes, potentially causing installation failures (denial of service); tampered content would fail signature/digest verification rather than being trusted.","cvssScore":3.9,"cvssSeverity":"LOW","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L","cwes":["CWE-378"],"vendors":[],"products":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-97026","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2542637","tags":[]},{"url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-r9w3-qx54-qvc8","tags":[]}],"exploitRefs":[{"url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-r9w3-qx54-qvc8","tags":[]}],"hasPoc":true,"ai":null}