Flatpak Downgrade via Unprivileged RemoveLocalRef on Multi-user Linux
CVE-2026-96281 Published on September 27, 2026
Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system apps/runtimes
On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the anti-downgrade check to fail to find a reference date. A malicious local user could use this to expose other users of the same system to an app version with unfixed vulnerabilities.
Vulnerability Analysis
CVE-2026-96281 can be exploited with physical access, requires user interaction and a small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
What is an Authorization Vulnerability?
The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVE-2026-96281 has been classified to as an Authorization vulnerability or weakness.
Products Associated with CVE-2026-96281
Want to know whenever a new CVE is published for Red Hat Enterprise Linux (RHEL)? stack.watch will email you.