Linuxsecurity Critical Flatpak Vulnerabilities Enable Sandbox Escape on Linux Systems
Article Content
- •Flatpak vulnerabilities allow sandboxed apps to escape and access host files.
- •Critical flaw due to missing symlink protection; CVE-2026-34078 has a severity score of 10.
- •Users are advised to upgrade to Flatpak version 1.18.1 to address these vulnerabilities.
Flatpak has disclosed several vulnerabilities, including a critical one allowing sandbox escape with full host access. This vulnerability enables a malicious app to gain arbitrary read and write access to host files, potentially escalating to arbitrary code execution. The flaw stems from inadequate symlink protection, allowing attackers to replace private directories with symlinks pointing to sensitive areas of the host system. The Flatpak 1.18.1 release addresses this and nine other severe vulnerabilities, with all older versions believed to be affected. Major Linux distributions, such as Fedora, have yet to push the latest version to stable releases. CVE IDs have been requested for all vulnerabilities, with two already assigned by Red Hat. The most severe vulnerability disclosed earlier, CVE-2026-34078, received a perfect 10 out of 10 severity score. Users are urged to upgrade to the latest stable release to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Fedora and CVE-2026-34078 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Flatpak Vulnerabilities Allow Host File Access and Deletion Two critical vulnerabilities in Flatpak, identified as CVE-2026-34078 and CVE-2026-34079, were discovered, allowing malicious applications to access files outside their sandbox or delete arbitrary files on the host system. These vulnerabilities stem from improper path validation in sandbox-expose options and when…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…