216.73.216.6

CVE-2026-34078

· Published 07/04/2026 22:16 · Modified 08/04/2026 21:27

Labels: CVE-2026-34078 2026-04-07CVE-2026-34078CWE-61[email protected]

Essential information

Published
07/04/2026 22:16
Modified
08/04/2026 21:27
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
flatpak / flatpak cpe:2.3:a:flatpak:flatpak:<1.16.4:*:*:*:*:*:*:*

References