CVE-2026-34078 Details
Description
Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4.
A critical vulnerability in Flatpak prior to version 1.16.4 allows applications to escape the sandbox and access host files, with the potential for executing code in the host context. This issue arises because the Flatpak portal's 'sandbox-expose' options can accept app-controlled symlinks that point to arbitrary paths. When these paths are resolved, Flatpak mounts the corresponding host files in the sandbox, granting apps unrestricted access to the host's file system.
Users can update to Flatpak version 1.16.4 or later to address this vulnerability. In the upcoming version 1.18.0, this issue will also be patched. As a temporary measure, the Flatpak Portal can be disabled, although this may cause some applications to misbehave.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | redhat-SADP |
| CWE-61 | UNIX Symbolic Link (Symlink) Following | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| flatpak flatpak | <= 1.16.3 |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 6, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 24, 2026 | Initial Analysis | [email protected] |
| Apr 11, 2026 | CVE Modified | CVE |
| Apr 9, 2026 | CVE Modified | CVE |
| Apr 7, 2026 | New CVE Received | [email protected] |