CVE-2026-97023: 
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-97023 is a path traversal vulnerability (via symlink following) in Flatpak's handling of the export/bin directory during app deployment that allows a malicious Flatpak app to cause deletion of attacker-chosen files outside the deployment directory when the app is installed or upgraded. In system-wide installations, the deletion is performed as root, significantly amplifying the impact. The vulnerability affects all Flatpak versions prior to 1.18.4 and was published on September 28, 2026. It carries a CVSS v3.1 base score of 7.1 (High) (Red Hat CVE, GitHub Advisory).

Technical details

The root cause is improper handling of symbolic links (CWE-61: UNIX Symbolic Link Following) when Flatpak processes the export/bin directory during app deployment. A malicious app can craft its deployment package to include symlinks in the export/bin directory that resolve to paths outside the intended deployment directory, causing Flatpak to delete those external files during installation or upgrade. The fix in version 1.18.4 introduces fd-relative operations for export/bin removal during deploy (commits 01cd7c4 and 40f1265), preventing symlink traversal outside the deployment directory. This vulnerability is related to CAPEC-27 (Leveraging Race Conditions via Symbolic Links) and overlaps with a related hardening effort tracked as GHSA-8xgq-v545-vgvf (GitHub Advisory, Red Hat CVE).

Impact

Successful exploitation allows an attacker to delete arbitrary files on the host system, with the severity escalating to root-level file deletion in system-wide Flatpak installations. There is no confidentiality impact (files are deleted, not read), but integrity is lowly impacted and availability is highly impacted — deletion of critical system files (e.g., configuration files, binaries, or libraries) could render the system unstable or unbootable. The attack does not cross a security scope boundary but the root-level deletion capability in system-wide deployments makes this particularly dangerous for Linux desktop and server environments (GitHub Advisory, Red Hat CVE).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the disclosure date. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction — a victim must install or upgrade a malicious Flatpak app — and no privileges are required from the attacker's side, making social engineering the primary attack vector. The NVD SSVC assessment classifies exploitation as "none" and technical impact as "partial" (Red Hat CVE, GitHub Advisory).

Exploitation steps

  1. Craft malicious Flatpak app: Create a Flatpak application package that includes a symlink within the export/bin directory pointing to a target file outside the deployment directory (e.g., export/bin/malicious-link -> ../../../../etc/passwd or another critical system file).
  2. Distribute the malicious app: Publish the crafted Flatpak app to a repository or distribute it directly (e.g., as a .flatpakref or .flatpak bundle file) to lure victims into installing it.
  3. Social engineer the victim: Convince a system administrator or user to install the malicious app, particularly via a system-wide installation (flatpak install --system) to trigger root-level file deletion.
  4. Trigger deployment: When the victim runs flatpak install or flatpak update for the malicious app, Flatpak processes the export/bin directory and follows the symlink, deleting the attacker-chosen file outside the deployment directory — as root in system-wide installations.
  5. Achieve objective: The targeted file (e.g., a critical system binary, configuration file, or security control) is deleted, potentially causing system instability, denial of service, or disabling security mechanisms (GitHub Advisory).

Indicators of compromise

  • File System: Unexpected deletion of files outside Flatpak deployment directories (e.g., /etc/, /usr/, /bin/) coinciding with a Flatpak install or upgrade event; presence of symlinks in ~/.local/share/flatpak/app/<appid>/current/active/export/bin/ or /var/lib/flatpak/app/<appid>/current/active/export/bin/ pointing to paths outside the deployment directory.
  • Logs: System logs (/var/log/syslog, journalctl) showing flatpak install or flatpak update operations followed by file-not-found errors or unexpected permission changes on system files; audit logs (auditd) recording file deletion events by the flatpak process or root outside expected Flatpak directories.
  • Process: flatpak process performing unlink() or remove() system calls on files outside /var/lib/flatpak/ or ~/.local/share/flatpak/ as observed via strace or auditd syscall monitoring.

Mitigation and workarounds

Upgrade Flatpak to version 1.18.4 or later, which fixes the vulnerability via fd-relative operations for export/bin removal during deployment (commits 01cd7c4 and 40f1265). As an interim workaround, avoid installing Flatpak apps from untrusted or unverified publishers, especially in system-wide deployments where deletions would be performed as root. Red Hat and the Flatpak project both recommend this trust-based mitigation for environments where immediate patching is not possible (GitHub Advisory, Red Hat CVE).

Community reactions

The vulnerability was credited to researcher Sebastian Wick (swick) and disclosed by smcv via the GitHub Security Advisory on September 28, 2026. Linux-focused media outlets including Linuxiac and Linux Compatible covered the Flatpak 1.18.4 release, highlighting it as fixing six security vulnerabilities including two root file-destruction bugs. Community discussion appeared on platforms including programming.dev and Privacy Guides forums, with general consensus that the trust-based workaround is practical for most users while patching is the definitive fix (Linuxiac, oss-sec).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

flatpak

Affected

sid

flatpak: 1.18.4-1

Fixed

trixie

flatpak: 1.16.6-1~deb13u3

Fixed

RHEL / CentOS

Affected

RHEL 8

flatpak.src

Affected

RHEL 9

flatpak.src

Affected

RHEL 10

flatpak.src

Affected

Source: This report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-97023HIGH7.1
  • Linux Debian logoLinux Debian
  • flatpak-devel
NoYesSep 28, 2026
CVE-2026-101913MEDIUM6.3
  • JavaScript logoJavaScript
  • node-ip-address
NoYesSep 28, 2026
CVE-2026-97026LOW3.9
  • Linux Debian logoLinux Debian
  • flatpak
NoYesSep 28, 2026
CVE-2026-97027LOW3.6
  • Linux Debian logoLinux Debian
  • flatpak.src
NoYesSep 28, 2026
CVE-2026-97025LOW3.2
  • Linux Debian logoLinux Debian
  • flatpak-selinux
NoYesSep 28, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management