CVE-2026-34079Disclosure(flatpak / flatpak)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch flatpak flatpak systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps to delete arbitrary files on the host. This vulnerability is fixed in 1.16.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flatpak

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-08); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
flatpak

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-08: 3Mentions · 2026-04-10: 1Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-04-10: 1Technical Details · 2026-04-08: 3Technical Details · 2026-04-10: 104-0804-10
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-083
Disclosure2Patch1
2026-04-101
Patch1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Patch

    4 security fixes in Flatpak https://www.openwall.com/lists/oss-security/2026/04/09/3 CVE-2026-34078: Complete sandbox escape leading to host file access and code execution in the host context (Critical) CVE-2026-34079: Arbitrary file deletion on the host filesystem (Moderate) and 2 non-CVEs (Low)

    Post summary

    The notice alerts readers to four Flatpak security fixes, including a critical sandbox escape and a moderate file‑deletion CVE, confirming patches are available without providing PoC or active exploitation details.

    120911.2K
    4.6K followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Flatpak sandbox escape and host filesystem exposure (CVE-2026-34078, CVE-2026-34079) 📅 **Timeline:** Disclosure: 2026-04-07, Patch: 2026-04-07 🆔 **CVE-2026-34078** | 📊 CVSS: 9.3 (CRITICAL 🔴) 🆔 **CVE-2026-34079** | 📊 CVSS: 8.7 (HIGH 🟠) 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Versions prior to 1.16.4 🔧 **Fixed Versions:** 1.16.4 🫨 **Attack Vectors:** - Network: app-controlled symlinks in sandbox-expose leading to host path mounts and sandbox escape (CVE-2026-34078) - Network: app-controlled cache path handling allowing deletion of arbitrary host files (CVE-2026-34079) 📝 **Summary:** Two Flatpak vulnerabilities let malicious apps break out of the sandbox and access or delete host files. CVE-2026-34078 uses app-controlled symlinks to mount host paths (possible code execution if chained), and CVE-2026-34079 allows arbitrary host file deletion via cache-path mishandling; both fixed in 1.16.4. 📈 **Impact Scope:** Unauthorized host file read/write/deletion; potential arbitrary code execution on host if sandbox escape is chained; affects systems running Flatpak versions prior to 1.16.4. 🛡️ **Recommended Actions:** - Update Flatpak to 1.16.4 immediately - Restrict installation of untrusted Flatpak apps and review app permissions 🪢 **Related Resources:** - https://www.helpnetsecurity.com/2026/04/08/flatpak-1-16-4-released-fixes-sandbox-escape/ - https://github.com/advisories/GHSA-2fxp-43j9-pwvc 🏷 **Tags:** #Cybersecurity #Flatpak #Linux

    Post summary

    The alert announces two critical Flatpak sandbox escape vulnerabilities that have been fixed in version 1.16.4, recommending immediate update and restricting untrusted apps.

    000007
    276 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34079 Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for http://ld.so removes outdated cache files without properly checking th… https://www.cve.org/CVERecord?id=CVE-2026-34079

    Post summary

    The post references CVE-2026-34079, indicating a flaw in Flatpak's caching mechanism that removes outdated files without adequate checks, but provides no PoC, exploit, patch, or reports of active exploitation.

    00000151
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-34079 Arbitrary File Deletion in Flatpak Prior to Version 1.16.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34079

    Post summary

    The text announces the disclosure of CVE-2026-34079, a vulnerability that allows arbitrary file deletion in Flatpak versions older than 1.16.4.

    0000041
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflatpakflatpak---

Explore more