Skip to content
Path Traversal Vulnerability in Flatpak (CVE-2026-97023)

Path Traversal Vulnerability in Flatpak (CVE-2026-97023)

First seen 28 Sep 2026, 21:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 21:09 UTC
  • •CVE-2026-97023 allows file deletion by malicious Flatpak apps.
  • •User interaction is necessary for exploitation; no remote attack possible.
  • •Patch released in Flatpak version 1.18.4; avoid untrusted app sources.

A path traversal vulnerability (CVE-2026-97023) in Flatpak's export/bin directory handling allows malicious apps to delete files outside their deployment directory during installation or upgrades. This issue affects Linux systems using Flatpak, particularly those with system-wide installations where deletions occur with root privileges. User interaction is required to exploit the vulnerability, as a user or administrator must install or upgrade the malicious app. The primary impact is on data integrity and availability, not confidentiality. Red Hat has issued a warning and recommends avoiding installations from untrusted publishers. The vulnerability was disclosed on September 28, 2026, and is currently not known to be actively exploited. A patch has been released in Flatpak version 1.18.4 to address this issue.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-28
CVE-2026-97023 published
Red Hat disclosed a path traversal vulnerability in Flatpak affecting Linux systems.
access.redhat.com
2026-09-28
Flatpak patch released
Flatpak version 1.18.4 was released to fix the path traversal vulnerability.
github.com

More articles in this cluster (3)

Following this threat?

Track CVE-2026-97023 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed