PT-2026-99723 · Flatpak · Flatpak

·

CVE-2026-96283

·

Published

2026-09-27

·

Updated

2026-09-28

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Flatpak (affected versions not specified)
Description A flaw exists in the flatpak-system-helper where calling the org.freedesktop.Flatpak.SystemHelper.CancelPull endpoint on a pull belonging to another user fails to actually cancel the operation. Instead, the pull is removed from internal tracking, which prevents the original owning user from being able to stop the ongoing pull.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96283

Affected Products

Flatpak