← Back to search

CVE-2026-96275

8.8 HIGHpublic exploit available

Published 2026-09-23 · Updated 2026-09-25

AI risk analysis

Summary
This flaw allows a malicious Flatpak repository to write attacker-controlled content to arbitrary locations on the host filesystem, potentially leading to privilege escalation or data loss.
Exploitability
Exploitation is moderately hard as it requires a compromised repository and the ability to manipulate file paths, but preconditions include system-level access.
Blast radius
If exploited, the impact could be severe, as it allows for arbitrary code execution with root privileges.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the affected feature or restrict access to the Flatpak repositories to trusted sources.
rcepriv-escalationflatpakfilesystemsymlink

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-22

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.