CVE-2026-34078Disclosure(flatpak / flatpak)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch flatpak flatpak systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-61CWE-59

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flatpak

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 14 mentions across 6 observed days
  • Momentum state: declining

What's happening

  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 9 signals
  • Disclosure: 7 classified signals
  • General: 3 classified signals
  • Peaked 4d ago at 6 mentions (2026-04-08); latest day: 1
  • 14 total mentions across 6 days

Affected systems

Vendors
Products
flatpak

Deep dive

Activity timeline14 mentions / 6d
02356Mentions · 2026-04-07: 1Mentions · 2026-04-08: 6Mentions · 2026-04-09: 4Mentions · 2026-04-10: 1Mentions · 2026-05-12: 1Mentions · 2026-05-13: 1PoC Mentioned / Linked · 2026-04-07: 1PoC Mentioned / Linked · 2026-04-08: 1PoC Mentioned / Linked · 2026-05-12: 1Patch / Workaround · 2026-04-08: 3Patch / Workaround · 2026-04-09: 2Technical Details · 2026-04-07: 1Technical Details · 2026-04-08: 3Technical Details · 2026-04-09: 3Technical Details · 2026-04-10: 1Technical Details · 2026-05-12: 104-0704-0804-0904-1005-1205-13
Signal classification3 categories
Disclosure
750.0%
Patch
428.6%
General
321.4%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-04-071
Disclosure1
2026-04-086
Disclosure3General1Patch2
2026-04-094
Disclosure1General1Patch2
2026-04-101
Disclosure1
2026-05-121
Disclosure1
2026-05-131
General1
Full discourse14 posts
  • 情報の灯台@joho_no_todai
    Disclosure

    「サンドボックス化」を売りにしてきたFlatpakが、そのサンドボックスを完全に突破される脆弱性を抱えていた。 CVE-2026-34078 シンボリックリンクを操作するだけで、ホストファイルへのアクセスとコード実行が可能になる。 SSHキーも、ブラウザの保存パスワードも、すべて露出しうる状態だった。 バージョン1.16.4で修正済み。 「サンドボックスだから安全」は、その中身を問わずに使える免罪符ではない。 https://joho-todai.com/flatpak-critical-vulnerability-sandbox-bypass/

    Post summary

    The text announces that Flatpak’s sandbox has been fully bypassed via symbolic link manipulation (CVE‑2026‑34078), explains the impact, and notes that version 1.16.4 contains a fix.

    0401531.2K
    9.7K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    4 security fixes in Flatpak https://www.openwall.com/lists/oss-security/2026/04/09/3 CVE-2026-34078: Complete sandbox escape leading to host file access and code execution in the host context (Critical) CVE-2026-34079: Arbitrary file deletion on the host filesystem (Moderate) and 2 non-CVEs (Low)

    Post summary

    The message reports two newly disclosed Flatpak CVEs: CVE‑2026‑34078 (sandbox escape with host code execution) and CVE‑2026‑34079 (arbitrary host file deletion), highlighting their critical and moderate severities.

    120911.2K
    4.6K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Critical 9.3 CVSS flaw (CVE-2026-34078) in Flatpak allows apps to escape sandboxes and access all host files. Secure your Linux system—update to v1.16.4 now! #Flatpak #LinuxSecurity #SandboxEscape #InfoSec #CyberSecurity #CVE #LinuxAdmin https://securityonline.info/flatpak-sandbox-escape-cve-2026-34078-linux-vulnerability/ https://t.co/PgfZ3lb3Pz

    Post summary

    The tweet highlights a critical CVE-2026-34078 in Flatpak that permits sandbox escape and urges users to patch to v1.16.4.

    04060532
    12.3K followersView on X
  • NanoVMs@nanovms
    General

    can we at least go a single week without some garbage ass container, in this case flatpak, escape? CVE-2026-34078 containers don't contain

    Post summary

    The message references CVE-2026-34078 in a flatpak context but provides no technical or actionable details.

    01041450
    2.2K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-34078 2 - CVE-2026-31431 3 - CVE-2024-27867 4 - CVE-2026-3854 5 - CVE-2026-34263 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    A brief list of five trending CVEs is shared, but no additional details on exploitation, patches, or technical specifics are provided.

    00011175
    1.7K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    CVE-2026-34078: escape de sandbox no Flatpak → acesso a todos os arquivos do host. A correção saiu em 2026, mas quantos sistemas ainda estão vulneráveis? Leia mais: 👉 https://tinyurl.com/528hyhzy #FreeSoftware #Flatpak https://t.co/t5ftvWBKq3

    Post summary

    The tweet highlights CVE‑2026‑34078, a Flatpak sandbox escape that allows full host file access, notes that a 2026 patch is available, and urges readers to check how many systems remain vulnerable.

    0001072
    1.5K followersView on X
  • SempreUpdate@SempreUpdate
    Patch

    Falha de segurança no Flatpak: vulnerabilidade crítica CVE-2026-34078 é corrigida na versão 1.16.4 https://sempreupdate.com.br/falha-de-seguranca-no-flatpak-cve-2026-34078-correcao-1-16-4/

    Post summary

    The article announces that CVE‑2026‑34078, a critical Flatpak vulnerability, has been fixed in version 1.16.4, with no mention of active exploits or PoC details.

    00010175
    4.7K followersView on X
  • Komodo Cyber Security@Komodosec
    Disclosure

    CVE-2026-34078: Complete sandbox escape leading to host file access and code execution in the host context https://github.com/flatpak/flatpak/security/advisories/GHSA-cc2q-qc34-jprg?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet announces CVE-2026-34078 as a sandbox escape that permits host file access and code execution, linking to a GitHub advisory that likely contains further technical details.

    0000030
    1.5K followersView on X
  • CrustyTL;DR@CrustyTLDR
    Disclosure

    📰 Flatpak: Complete Sandbox Escape A critical vulnerability, CVE-2026-34078, has been discovered in Flatpak, allowing for a complete sandbox escape. This flaw grants attackers access to host files and enables ... http://crustylabs.ai #TechNews #CrustyTLDR

    Post summary

    The post announces the discovery of CVE‑2026‑34078 in Flatpak, noting it is a critical sandbox escape that gives host file access, but it does not provide PoC, patch, or evidence of active exploitation.

    0000030
    4 followersView on X
  • Mas73r@Mas73r
    General

    CVE-2026-34078 https://security-tracker.debian.org/tracker/CVE-2026-34078

    Post summary

    The tweet simply lists CVE-2026-34078 and links to Debian’s security tracker, with no additional details on exploitation, patches, or vulnerability specifics.

    0000034
    469 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Flatpak sandbox escape and host filesystem exposure (CVE-2026-34078, CVE-2026-34079) 📅 **Timeline:** Disclosure: 2026-04-07, Patch: 2026-04-07 🆔 **CVE-2026-34078** | 📊 CVSS: 9.3 (CRITICAL 🔴) 🆔 **CVE-2026-34079** | 📊 CVSS: 8.7 (HIGH 🟠) 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Versions prior to 1.16.4 🔧 **Fixed Versions:** 1.16.4 🫨 **Attack Vectors:** - Network: app-controlled symlinks in sandbox-expose leading to host path mounts and sandbox escape (CVE-2026-34078) - Network: app-controlled cache path handling allowing deletion of arbitrary host files (CVE-2026-34079) 📝 **Summary:** Two Flatpak vulnerabilities let malicious apps break out of the sandbox and access or delete host files. CVE-2026-34078 uses app-controlled symlinks to mount host paths (possible code execution if chained), and CVE-2026-34079 allows arbitrary host file deletion via cache-path mishandling; both fixed in 1.16.4. 📈 **Impact Scope:** Unauthorized host file read/write/deletion; potential arbitrary code execution on host if sandbox escape is chained; affects systems running Flatpak versions prior to 1.16.4. 🛡️ **Recommended Actions:** - Update Flatpak to 1.16.4 immediately - Restrict installation of untrusted Flatpak apps and review app permissions 🪢 **Related Resources:** - https://www.helpnetsecurity.com/2026/04/08/flatpak-1-16-4-released-fixes-sandbox-escape/ - https://github.com/advisories/GHSA-2fxp-43j9-pwvc 🏷 **Tags:** #Cybersecurity #Flatpak #Linux

    Post summary

    Flatpak sandbox escape vulnerabilities CVE‑2026‑34078 and CVE‑2026‑34079 allow malicious apps to break out of the sandbox and access or delete host files; they are fixed in Flatpak 1.16.4 and users should update immediately.

    000007
    276 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34078 Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app… https://www.cve.org/CVERecord?id=CVE-2026-34078

    Post summary

    The text provides a concise disclosure of CVE‑2026‑34078, noting a design issue in older Flatpak versions, but offers no proof‑of‑concept, exploit details, or patch information.

    00000193
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-34078 Arbitrary Path Access via Symlink Traversal in Flatpak Before 1.16.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34078

    Post summary

    A new CVE-2026-34078 is disclosed for Flatpak versions before 1.16.4, permitting arbitrary path access via symlink traversal.

    0000043
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34078: Flatpak has a complete sandbox e... Symlink traversal through portal sandbox-expose options = instant host breakout with full filesystem access and RCE - F... https://zerodaysignal.com/vulnerability/CVE-2026-34078 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-34078, detailing that Flatpak’s sandbox can be bypassed via symlink traversal to achieve RCE and full filesystem access, and links to an external site for more information.

    0000065
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflatpakflatpak---

Explore more