Skip to content
CVE Alert: CVE-2026-97023 – Red Hat

CVE Alert: CVE-2026-97023 – Red Hat

Redpacketsecurity •admin • September 28, 2026

A path traversal vulnerability in Flatpak’s handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside the deployment directory when the app is installed or upgraded. In system-wide installations, the deletion is performed as root.

**Risk verdict:** Address promptly on Linux hosts that install Flatpak applications, but the supplied signals do not establish active exploitation or justify an emergency-wide response.

**Why this matters:** A malicious application could turn a routine installation or upgrade into deletion of files outside its own deployment area, potentially disrupting services or damaging host data. System-wide deployment increases the consequence because the operation may run with root authority; the expected impact is primarily availability and data integrity, not confidentiality.

**Most likely attack path:** The network attack rating does not mean an attacker can trigger this remotely without an intermediary: a user or administrator must install or upgrade a malicious app. No privileges are required by the vulnerability itself, but user interaction is required; low complexity makes the path practical once that action occurs. Scope is unchanged, so impact is on the affected host rather than indicating direct cross-system compromise.

**Who is most exposed:** Linux desktop and workstation fleets using Flatpak are relevant, especially where apps are installed system-wide or sourced from less-trusted publishers. The available data does not identify affected deployment configurations in detail.

Alert on Flatpak install or upgrade events followed by unexpected file deletions.

Audit deletions outside Flatpak deployment paths, recording process, user and target path.

Review package-manager and system logs for unapproved app sources or recent deployments.

Mitigation and prioritisation

Apply the vendor’s fixed package when available; confirm remediation status before scheduling.

Avoid system-wide installs from untrusted publishers; restrict app sources and installation rights.

Back up critical host files and validate changes in a representative test group.

KEV and EPSS data were not supplied; SSVC reports no exploitation, so prioritise exposure and deployment scope.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

CWE Weaknesses (1)

Platforms (2)

Vulnerabilities (1)