Flatpak could be made to access files outside its sandbox or delete arbitrary files on the host.
flatpak - Application deployment framework for desktop apps
It was discovered that Flatpak did not properly validate paths in sandbox-expose options. A malicious or compromised Flatpak app could use app-controlled symlinks to access arbitrary host files and gain code execution in the host context. This issue was addressed in Ubuntu Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. ( CVE-2026-34078 ) It was discovered that Flatpak did not properly validate paths when removing outdated ld.so cache files. A malicious or compromised Flatpak app could use this issue to delete arbitrary files on the host. ( CVE-2026-34079 )
It was discovered that Flatpak did not properly validate paths in sandbox-expose options. A malicious or compromised Flatpak app could use app-controlled symlinks to access arbitrary host files and gain code execution in the host context. This issue was addressed in Ubuntu Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. ( CVE-2026-34078 )
It was discovered that Flatpak did not properly validate paths when removing outdated ld.so cache files. A malicious or compromised Flatpak app could use this issue to delete arbitrary files on the host. ( CVE-2026-34079 )
It was discovered that Flatpak did not properly validate paths in sandbox-expose options. A malicious or compromised Flatpak app could use app-controlled symlinks to access arbitrary host files and gain code execution in the host context. This issue was addressed in Ubuntu Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. ( CVE-2026-34078 ) It was discovered that Flatpak did not properly validate paths when removing outdated ld.so cache files. A malicious or compromised Flatpak app could use this issue to delete arbitrary files on the host. ( CVE-2026-34079 )
It was discovered that Flatpak did not properly validate paths in sandbox-expose options. A malicious or compromised Flatpak app could use app-controlled symlinks to access arbitrary host files and gain code execution in the host context. This issue was addressed in Ubuntu Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. ( CVE-2026-34078 )
It was discovered that Flatpak did not properly validate paths when removing outdated ld.so cache files. A malicious or compromised Flatpak app could use this issue to delete arbitrary files on the host. ( CVE-2026-34079 )
In general, a standard system update will make all the necessary changes.
The problem can be corrected by updating your system to the following package versions:
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
