Critical Flatpak Vulnerabilities Enable Sandbox Escape on Linux Systems

Critical Flatpak Vulnerabilities Enable Sandbox Escape on Linux Systems

First seen 14 Aug 2026, 13:29 UTC CybernewsLinuxsecurity 71% similarity 72.6

Article Content

Browse articles
ThreatCluster

Flatpak has disclosed several vulnerabilities, including a critical one allowing sandbox escape with full host access. This vulnerability enables a malicious app to gain arbitrary read and write access to host files, potentially escalating to arbitrary code execution. The flaw stems from inadequate symlink protection, allowing attackers to replace private directories with symlinks pointing to sensitive areas of the host system. The Flatpak 1.18.1 release addresses this and nine other severe vulnerabilities, with all older versions believed to be affected. Major Linux distributions, such as Fedora, have yet to push the latest version to stable releases. CVE IDs have been requested for all vulnerabilities, with two already assigned by Red Hat. The most severe vulnerability disclosed earlier, CVE-2026-34078, received a perfect 10 out of 10 severity score. Users are urged to upgrade to the latest stable release to mitigate risks.

Key Points: • Flatpak vulnerabilities allow sandboxed apps to escape and access host files. • Critical flaw due to missing symlink protection; CVE-2026-34078 has a severity score of 10. • Users are advised to upgrade to Flatpak version 1.18.1 to address these vulnerabilities.

ThreatCluster AI How this analysis works

Timeline

2026-04-07
CVE-2026-34078 published
A critical vulnerability in Flatpak was disclosed, allowing sandbox escape with a severity score of 10.
Cybernews
2026-08-12
Flatpak 1.18.1 released
Flatpak released version 1.18.1 to address multiple vulnerabilities, including critical sandbox escape issues.
Cybernews
2026-08-14
Fedora updates Flatpak to 1.18.1
Fedora issued a security advisory for Flatpak 1.18.1, urging users to upgrade to mitigate vulnerabilities.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story