Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Avoid installing Flatpak extensions from non-trusted sources.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 27 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host directory listings can be disclosed to sandboxed applications using the extension. Additionally, unvalidated extension metadata can cause extension content to be mounted at unintended locations inside the sandbox. | |
| Title | Flatpak: flatpak: extension metadata path traversal file existence oracle | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-59 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-28T12:58:34.403Z
Reserved: 2026-09-22T20:43:56.596Z
Link: CVE-2026-96282
Updated: 2026-09-28T12:58:29.027Z
Status : Received
Published: 2026-09-27T22:17:06.430
Modified: 2026-09-28T13:17:25.767
Link: CVE-2026-96282
No data.
OpenCVE Enrichment
Updated: 2026-09-28T00:30:07Z