๐Ÿ” CVE Alert

CVE-2026-34078

CRITICAL 9.0

Flatpak has a complete sandbox escape leading to host file access and code execution in the host context

CVSS Score
9.0
EPSS Score
0.0%
EPSS Percentile
0th

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4.

CWE CWE-61
Vendor flatpak
Product flatpak
Published Apr 7, 2026
Last Updated Jul 15, 2026
Stay Ahead of the Next One

Get instant alerts for flatpak flatpak

Be the first to know when new critical vulnerabilities affecting flatpak flatpak are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

flatpak / flatpak
< 1.16.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/flatpak/flatpak/security/advisories/GHSA-cc2q-qc34-jprg openwall.com: http://www.openwall.com/lists/oss-security/2026/04/09/8 openwall.com: http://www.openwall.com/lists/oss-security/2026/04/10/14 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-34078 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2456276 security.access.redhat.com: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34078.json access.redhat.com: https://access.redhat.com/errata/RHSA-2026:35843 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:23420 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:21757 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:21756 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:30901 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:25381 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:25068 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:23419 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:23417 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:23418 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:21755