CVE-2026-96284

A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the system helper follow symlinks when importing OCI images that are under the user's control.

  • Published Sep 27, 2026
  • CVSS 2.5 low
  • 0.1% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-96284 at the National Vulnerability Database