
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34079 is a path traversal vulnerability in Flatpak, the Linux application sandboxing and distribution framework, that allows any Flatpak application to delete arbitrary files on the host filesystem. The flaw affects all Flatpak versions prior to 1.16.4 and was disclosed on April 7, 2026, with a fix released in version 1.16.4. It was reported by Codean Labs and assigned a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Feedly).
The root cause is improper path validation (CWE-22: Path Traversal) in Flatpak's ld.so cache management logic. When the caching mechanism removes outdated cache files, it fails to verify that the app-controlled path to the outdated cache actually resides within the designated cache directory. Because Flatpak apps can influence this path, a malicious or compromised app can craft a path that traverses outside the cache directory, causing the cache cleanup routine to delete arbitrary files on the host system. No special privileges or user interaction are required for exploitation (GitHub Advisory, Feedly).
Successful exploitation allows any Flatpak application — including untrusted ones installed from Flathub or other repositories — to delete arbitrary files on the host system without requiring elevated privileges or user interaction. This can result in deletion of critical system files, data loss, compromise of system integrity, and potential denial of service if essential OS components are removed. While the vulnerability does not directly expose confidential data or provide code execution, the ability to delete system files could be chained with other techniques to destabilize or further compromise the host (GitHub Advisory, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.202%, indicating a low probability of exploitation in the near term. Detection plugins have been released by Nessus and Qualys, enabling vulnerability scanning across affected systems (Feedly).
../../ sequences) to point to a target file on the host filesystem.ld.so cache management routine to run, which processes the attacker-controlled path without validating that it resides within the cache directory./etc/, /usr/, /lib/); missing ld.so.cache or other critical linker/loader files.journalctl, /var/log/syslog) showing file-not-found errors for previously existing system files; Flatpak runtime logs referencing unusual cache paths containing ../ sequences.flatpak-session-helper, bwrap) accessing file paths outside expected sandbox and cache directories.The vulnerability is fixed in Flatpak version 1.16.4, and a fix is also planned for the upcoming version 1.18.0. Users should upgrade Flatpak to 1.16.4 or later immediately. No known configuration-based workaround exists other than updating; as a temporary measure, administrators may consider limiting or disabling untrusted Flatpak applications until patching is complete. Downstream distributions including Debian, openSUSE, Red Hat Enterprise Linux, AlmaLinux, Rocky Linux, Amazon Linux 2023, and Mageia have released updated packages (GitHub Advisory, Red Hat Errata, openSUSE Advisory).
The vulnerability received notable coverage from Linux-focused media outlets including 9to5Linux, Linuxiac, XDA Developers, and Help Net Security, which highlighted it as a critical sandbox escape issue (9to5Linux, Linuxiac, Help Net Security). Hackaday's weekly security roundup also featured the flaw (Hackaday). The oss-security mailing list carried the disclosure, and the vulnerability was credited to Codean Labs (oss-security, GitHub Advisory). Community sentiment reflected concern about sandbox integrity, given that the flaw affects all Flatpak apps regardless of trust level.
Fix availability across major Linux distributions and their releases.
bookworm
flatpak: 1.14.10-1~deb12u2
sid
flatpak: 1.16.4-1
trixie
flatpak: 1.16.6-1~deb13u1
bionic (esm-apps)
flatpak: 1.0.9-0ubuntu0.4+esm1
devel
flatpak
focal (esm-apps)
flatpak: 1.6.5-0ubuntu0.5+esm1
jammy
flatpak
jammy (esm-apps)
flatpak: 1.12.7-1ubuntu0.1+esm1
noble
flatpak
noble (esm-apps)
flatpak: 1.14.6-1ubuntu0.1+esm1
resolute
flatpak
RHEL 8
:appstream:flatpak-0:1.12.9-4.el8_10.src
RHEL 9
:appstream:flatpak-0:1.12.7-5.el9_2.1.src
RHEL 10
flatpak-0:1.16.0-5.el10_0.2.src
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."