{"id":"CVE-2026-96283","title":"By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to stop it","summary":"By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to stop it. Ongoing pulls cannot be stopped.","severity":"low","cvss":3.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-862"],"vendor":"Red Hat","product":"flatpak","affected":["flatpak (all versions)","flatpak (all versions)","flatpak (all versions)","flatpak (all versions)"],"published":"2026-09-27","updated":"2026-09-27","sourceUpdated":"2026-09-27T23:17:01.037","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-96283","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-96283","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2539424","label":"secalert@redhat.com"},{"url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-89xm-3m96-w3jg","label":"secalert@redhat.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-27T22:59:18.878Z","slug":"CVE-2026-96283","body":"## Overview\n\nBy calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to stop it. Ongoing pulls cannot be stopped.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":18,"depthScoreParts":{"impact":18.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}