PT-2026-99719 · Flatpak · Flatpak
CVSS v3.1
6.2
Medium
| Vector | AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Flatpak (affected versions not specified)
Description
On multi-user systems, a local user with an active session can downgrade a system-wide application to an older version. This is achieved by removing the application's remote reference using the unprivileged system-helper
RemoveLocalRef() method, which causes the anti-downgrade check to fail because it cannot find a reference date. This action allows a malicious actor to expose other users on the same system to software versions containing known security flaws.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flatpak