LOW 2.5 NVD

CVE-2026-96284

A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the s

A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the system helper follow symlinks when importing OCI images that are under the user's control.

References

Published: 2026-09-27 · Source: NVD · Feed updated: 2026-09-28
This low severity vulnerability with a CVSS score of 2.5 was published on 2026-09-27 via NVD.
vulnfeed aggregates 11721 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.