CVE-2026-97026: 
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-97026 is a local privilege-adjacent vulnerability in Flatpak where temporary child repository directories are created under the user cache with world-writable permissions (mode 0777). On multi-user systems with a permissive umask, other local users can read or modify these directories during app or runtime installation, potentially causing installation failures (denial of service). The vulnerability was discovered by AISLE in cooperation with Red Hat and publicly disclosed on September 28, 2026. It affects all Flatpak versions prior to 1.18.4. It carries a CVSS v3.1 base score of 3.9 (Low) (Red Hat CVE, GitHub Advisory).

Technical details

The root cause is classified as CWE-378 (Creation of Temporary File With Insecure Permissions). Flatpak's system-helper allocates child temporary directories under /var/tmp/flatpak-cache-* with mode 0777, meaning any local user can read or write to these directories if the process's umask does not restrict other-user permissions. The flatpak(1) CLI, GNOME Software, and KDE Plasma Discover are believed unaffected because they explicitly set umask 022 during initialization, limiting cache directory permissions to 0755; however, other software using libflatpak with a permissive umask may be indirectly vulnerable. The fix (commit 011dfae2) restricts tmpdir permissions from 0777 to 0755 (GitHub Advisory, Red Hat Bugzilla).

Impact

A local attacker on a multi-user system can read the contents of the temporary installation directory (limited confidentiality impact) or modify them to cause installation failures, constituting a denial of service. Critically, any tampered app or runtime content will fail Flatpak's signature or digest verification and will not be executed, so the integrity threat is effectively mitigated by cryptographic checks. The scope of impact is limited to the local system and does not enable lateral movement or privilege escalation (GitHub Advisory, Red Hat CVE).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires local access, low privileges, and user interaction (a legitimate user must be performing a Flatpak installation), making opportunistic exploitation unlikely (Red Hat CVE, GitHub Advisory).

Exploitation steps

  1. Identify a vulnerable target: Confirm the target is a multi-user Linux system running Flatpak < 1.18.4 where the Flatpak-using process (e.g., a custom libflatpak consumer) does not set a restrictive umask.
  2. Wait for or trigger an installation: Monitor or wait for a legitimate user or service to initiate a Flatpak app or runtime installation, which causes Flatpak to create a temporary directory under /var/tmp/flatpak-cache-*/ with mode 0777.
  3. Locate the world-writable directory: As a local unprivileged user, enumerate /var/tmp/flatpak-cache-*/ to find the newly created child temporary repository directory.
  4. Read or modify contents: Read files in the directory to access partially downloaded app/runtime data (limited confidentiality impact), or overwrite/corrupt files to cause the installation to fail (denial of service). Note: any modified content will fail Flatpak's signature/digest verification and will not be installed or executed. (GitHub Advisory, Red Hat Bugzilla)

Indicators of compromise

  • File System: Unexpected modification timestamps or file ownership changes on directories under /var/tmp/flatpak-cache-*/ during or after a Flatpak installation; directories under /var/tmp/flatpak-cache-*/ with permissions drwxrwxrwx (0777) on unpatched systems.
  • Logs: Flatpak installation failures or signature/digest verification errors in system logs (e.g., journalctl) coinciding with active local user sessions; warnings from flatpak-system-helper about falling back to inefficient repository copying (may indicate overly restrictive umask as a workaround).
  • Process: Unexpected access to /var/tmp/flatpak-cache-*/ by processes belonging to users other than the one performing the installation, visible via auditd or inotifywait monitoring on the cache path. (GitHub Advisory, Red Hat CVE)

Mitigation and workarounds

Upgrade Flatpak to version 1.18.4 or later, which restricts temporary directory permissions from 0777 to 0755 via commit 011dfae2. As an immediate workaround without upgrading, set a umask of 022 or more restrictive (e.g., 027 or 077) for any process using libflatpak; note that umasks more restrictive than 022 (e.g., 027) will prevent flatpak-system-helper from reading the temporary directory directly, causing an inefficient fallback with a warning. The flatpak(1) CLI, GNOME Software, and KDE Plasma Discover are not affected as they already enforce umask 022 (GitHub Advisory, Red Hat CVE).

Community reactions

The vulnerability was reported by AISLE in cooperation with Red Hat and received coverage from Linux-focused outlets including Linuxiac, which noted it as one of six security fixes in the Flatpak 1.18.4 release. Community discussion appeared on platforms such as programming.dev and Privacy Guides forums, with general consensus that the low severity and cryptographic mitigations limit real-world risk. The oss-security mailing list also carried a disclosure notice (Linuxiac, oss-sec).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

flatpak

Affected

sid

flatpak: 1.18.4-1

Fixed

trixie

flatpak: 1.16.6-1~deb13u3

Fixed

RHEL / CentOS

Affected

RHEL 8

flatpak.src

Affected

RHEL 9

flatpak.src

Affected

RHEL 10

flatpak.src

Affected

Source: This report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-97023HIGH7.1
  • Linux Debian logoLinux Debian
  • flatpak-devel
NoYesSep 28, 2026
CVE-2026-101913MEDIUM6.3
  • JavaScript logoJavaScript
  • node-ip-address
NoYesSep 28, 2026
CVE-2026-97026LOW3.9
  • Linux Debian logoLinux Debian
  • flatpak
NoYesSep 28, 2026
CVE-2026-97027LOW3.6
  • Linux Debian logoLinux Debian
  • flatpak.src
NoYesSep 28, 2026
CVE-2026-97025LOW3.2
  • Linux Debian logoLinux Debian
  • flatpak-selinux
NoYesSep 28, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management