On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the anti-downgrade check to fail to find a reference date. A malicious local user could use this to expose other users of the same system to an app version with unfixed vulnerabilities.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
Ensure that Flatpak apps installed system-wide are fully updated before running them.
References
History
Sun, 27 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Sun, 27 Sep 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the anti-downgrade check to fail to find a reference date. A malicious local user could use this to expose other users of the same system to an app version with unfixed vulnerabilities. | |
| Title | Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system apps/runtimes | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-284 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-27T21:16:34.274Z
Reserved: 2026-09-22T20:43:45.571Z
Link: CVE-2026-96281
No data.
Status : Received
Published: 2026-09-27T21:17:04.330
Modified: 2026-09-27T21:17:04.330
Link: CVE-2026-96281
No data.
OpenCVE Enrichment
No data.
Weaknesses