CVE-2026-96275
8.8 HIGHpublic exploit availablePublished 2026-09-23 · Updated 2026-09-25
AI risk analysis
- Summary
- This flaw allows a malicious Flatpak repository to write attacker-controlled content to arbitrary locations on the host filesystem, potentially leading to privilege escalation or data loss.
- Exploitability
- Exploitation is moderately hard as it requires a compromised repository and the ability to manipulate file paths, but preconditions include system-level access.
- Blast radius
- If exploited, the impact could be severe, as it allows for arbitrary code execution with root privileges.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Disable the affected feature or restrict access to the Flatpak repositories to trusted sources.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-22
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-101894PoC
- CRITICALCVE-2026-85526PoC
- CRITICALCVE-2026-88624PoC
- HIGHCVE-2025-14754
- CRITICALCVE-2026-100715PoC
- CRITICALCVE-2026-20307
- CRITICALCVE-2026-65113PoC
- HIGHCVE-2026-81469
Related by shared AI tags and CWE weakness class. Browse the full archive.