Threat intelligence dashboard
CVE-2026-97023high

Flatpak: flatpak: arbitrary file deletion in root context via path traversal in deploy directory export/bin

A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside the deployment directory when the app is installed or upgraded. In system-wide installations, the deletion is performed as root.

Risk score

7.1

CVSS 3.1

Vendor
Red Hat
Product
Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
CWE
CWE-61
Published
Sep 28, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

Red Hat Enterprise Linux 10

Red Hat

No affected version range was provided.

Red Hat Enterprise Linux 7

Red Hat

No affected version range was provided.

Red Hat Enterprise Linux 8

Red Hat

No affected version range was provided.

Red Hat Enterprise Linux 9

Red Hat

No affected version range was provided.

Technical metrics

7.1

CVSS 3.1

Severity
high
Source
redhat
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H