In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925. Flatpak creates a few app data directories (e.g., /var/cache, /var/data, /var/config, and /var/tmp) in every sandbox on every app launch where, in some cases, components of the path are attacker-controlled. Missing symlink protection can redirect the directories. Some of these directories are bind-mounted by Flatpak by passing the path (e.g., /home/user/.var/app/APP_ID/cache/tmp), which contains attacker-controlled directories (tmp) to bwrap --bind SRC DST. bwrap passes the path on to the kernel, which then follows symlinks. A malicious symlink can point to arbitrary locations on the host and it will become mounted inside the sandbox.
Advisories
No advisories yet.
Fixes
Solution
https://github.com/flatpak/flatpak/commit/478072972056d2d15c768c246f80abdf83cf0e5e
Workaround
No workaround given by the vendor.
References
History
Sat, 12 Sep 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925. Flatpak creates a few app data directories (e.g., /var/cache, /var/data, /var/config, and /var/tmp) in every sandbox on every app launch where, in some cases, components of the path are attacker-controlled. Missing symlink protection can redirect the directories. Some of these directories are bind-mounted by Flatpak by passing the path (e.g., /home/user/.var/app/APP_ID/cache/tmp), which contains attacker-controlled directories (tmp) to bwrap --bind SRC DST. bwrap passes the path on to the kernel, which then follows symlinks. A malicious symlink can point to arbitrary locations on the host and it will become mounted inside the sandbox. | |
| First Time appeared |
Flatpak
Flatpak flatpak |
|
| Weaknesses | CWE-61 | |
| CPEs | cpe:2.3:a:flatpak:flatpak:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Flatpak
Flatpak flatpak |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-12T20:00:58.476Z
Reserved: 2026-09-12T20:00:58.046Z
Link: CVE-2026-90616
No data.
Status : Received
Published: 2026-09-12T20:16:30.957
Modified: 2026-09-12T20:16:30.957
Link: CVE-2026-90616
No data.
OpenCVE Enrichment
No data.
Weaknesses