Redpacketsecurity Path Traversal Vulnerability in Flatpak (CVE-2026-97023)
Article Content
- •CVE-2026-97023 allows file deletion by malicious Flatpak apps.
- •User interaction is necessary for exploitation; no remote attack possible.
- •Patch released in Flatpak version 1.18.4; avoid untrusted app sources.
A path traversal vulnerability (CVE-2026-97023) in Flatpak's export/bin directory handling allows malicious apps to delete files outside their deployment directory during installation or upgrades. This issue affects Linux systems using Flatpak, particularly those with system-wide installations where deletions occur with root privileges. User interaction is required to exploit the vulnerability, as a user or administrator must install or upgrade the malicious app. The primary impact is on data integrity and availability, not confidentiality. Red Hat has issued a warning and recommends avoiding installations from untrusted publishers. The vulnerability was disclosed on September 28, 2026, and is currently not known to be actively exploited. A patch has been released in Flatpak version 1.18.4 to address this issue.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-97023 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…