{"id":"CVE-2026-96281","title":"On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the anti-d…","summary":"On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the anti-d…","severity":"medium","cvss":6.2,"cvssVector":"CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-284"],"vendor":"Red Hat","product":"flatpak","affected":["flatpak (all versions)","flatpak (all versions)","flatpak (all versions)","flatpak (all versions)"],"published":"2026-09-27","updated":"2026-09-27","sourceUpdated":"2026-09-27T21:17:04.330","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-96281","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-96281","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2539421","label":"secalert@redhat.com"},{"url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-q4gr-vc25-57m5","label":"secalert@redhat.com"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-09-27T21:58:39.827Z","slug":"CVE-2026-96281","body":"## Overview\n\nOn a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the anti-downgrade check to fail to find a reference date. A malicious local user could use this to expose other users of the same system to an app version with unfixed vulnerabilities.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":34.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}