CVE-2026-34079
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-34079 is a path traversal vulnerability in Flatpak, the Linux application sandboxing and distribution framework, that allows any Flatpak application to delete arbitrary files on the host filesystem. The flaw affects all Flatpak versions prior to 1.16.4 and was disclosed on April 7, 2026, with a fix released in version 1.16.4. It was reported by Codean Labs and assigned a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Feedly).

Technical details

The root cause is improper path validation (CWE-22: Path Traversal) in Flatpak's ld.so cache management logic. When the caching mechanism removes outdated cache files, it fails to verify that the app-controlled path to the outdated cache actually resides within the designated cache directory. Because Flatpak apps can influence this path, a malicious or compromised app can craft a path that traverses outside the cache directory, causing the cache cleanup routine to delete arbitrary files on the host system. No special privileges or user interaction are required for exploitation (GitHub Advisory, Feedly).

Impact

Successful exploitation allows any Flatpak application — including untrusted ones installed from Flathub or other repositories — to delete arbitrary files on the host system without requiring elevated privileges or user interaction. This can result in deletion of critical system files, data loss, compromise of system integrity, and potential denial of service if essential OS components are removed. While the vulnerability does not directly expose confidential data or provide code execution, the ability to delete system files could be chained with other techniques to destabilize or further compromise the host (GitHub Advisory, Feedly).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.202%, indicating a low probability of exploitation in the near term. Detection plugins have been released by Nessus and Qualys, enabling vulnerability scanning across affected systems (Feedly).

Exploitation steps

  1. Install or control a Flatpak app: An attacker packages or compromises a Flatpak application and installs it on a target system running Flatpak prior to version 1.16.4.
  2. Manipulate the ld.so cache path: From within the Flatpak sandbox, the malicious app crafts a path that traverses outside the expected cache directory (e.g., using ../../ sequences) to point to a target file on the host filesystem.
  3. Trigger cache cleanup: The app triggers or waits for Flatpak's ld.so cache management routine to run, which processes the attacker-controlled path without validating that it resides within the cache directory.
  4. Arbitrary file deletion: The cache cleanup routine deletes the file at the attacker-specified path on the host, which could be a critical system file, configuration file, or security-relevant artifact (GitHub Advisory, Feedly).

Indicators of compromise

  • File System: Unexpected deletion of system files or configuration files outside of Flatpak's cache directory (e.g., /etc/, /usr/, /lib/); missing ld.so.cache or other critical linker/loader files.
  • Logs: System logs (e.g., journalctl, /var/log/syslog) showing file-not-found errors for previously existing system files; Flatpak runtime logs referencing unusual cache paths containing ../ sequences.
  • Process: Flatpak helper processes (e.g., flatpak-session-helper, bwrap) accessing file paths outside expected sandbox and cache directories.
  • Network: No specific network IOCs identified, as exploitation is local to the host via the Flatpak sandbox mechanism.

Mitigation and workarounds

The vulnerability is fixed in Flatpak version 1.16.4, and a fix is also planned for the upcoming version 1.18.0. Users should upgrade Flatpak to 1.16.4 or later immediately. No known configuration-based workaround exists other than updating; as a temporary measure, administrators may consider limiting or disabling untrusted Flatpak applications until patching is complete. Downstream distributions including Debian, openSUSE, Red Hat Enterprise Linux, AlmaLinux, Rocky Linux, Amazon Linux 2023, and Mageia have released updated packages (GitHub Advisory, Red Hat Errata, openSUSE Advisory).

Community reactions

The vulnerability received notable coverage from Linux-focused media outlets including 9to5Linux, Linuxiac, XDA Developers, and Help Net Security, which highlighted it as a critical sandbox escape issue (9to5Linux, Linuxiac, Help Net Security). Hackaday's weekly security roundup also featured the flaw (Hackaday). The oss-security mailing list carried the disclosure, and the vulnerability was credited to Codean Labs (oss-security, GitHub Advisory). Community sentiment reflected concern about sandbox integrity, given that the flaw affects all Flatpak apps regardless of trust level.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

flatpak: 1.14.10-1~deb12u2

Fixed

sid

flatpak: 1.16.4-1

Fixed

trixie

flatpak: 1.16.6-1~deb13u1

Fixed

Ubuntu

Fixed

bionic (esm-apps)

flatpak: 1.0.9-0ubuntu0.4+esm1

Fixed

devel

flatpak

Not Affected

focal (esm-apps)

flatpak: 1.6.5-0ubuntu0.5+esm1

Fixed

jammy

flatpak

Affected

jammy (esm-apps)

flatpak: 1.12.7-1ubuntu0.1+esm1

Fixed

noble

flatpak

Affected

noble (esm-apps)

flatpak: 1.14.6-1ubuntu0.1+esm1

Fixed

resolute

flatpak

Not Affected

RHEL / CentOS

Fixed

RHEL 8

:appstream:flatpak-0:1.12.9-4.el8_10.src

Fixed

RHEL 9

:appstream:flatpak-0:1.12.7-5.el9_2.1.src

Fixed

RHEL 10

flatpak-0:1.16.0-5.el10_0.2.src

Fixed

Alpine

Fixed

edge

flatpak: 1.16.4-r0

Fixed

v3.23

flatpak: 1.16.4-r0

Fixed

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86738CRITICAL9.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86734HIGH7.1
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86735MEDIUM5.9
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86737MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86736MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management