PT-2026-99719 · Flatpak · Flatpak

·

CVE-2026-96281

·

Published

2026-09-27

·

Updated

2026-09-27

CVSS v3.1

6.2

Medium

VectorAV:P/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Flatpak (affected versions not specified)
Description On multi-user systems, a local user with an active session can downgrade a system-wide application to an older version. This is achieved by removing the application's remote reference using the unprivileged system-helper RemoveLocalRef() method, which causes the anti-downgrade check to fail because it cannot find a reference date. This action allows a malicious actor to expose other users on the same system to software versions containing known security flaws.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96281

Affected Products

Flatpak