---
id: CVE-2026-96283
title: >-
  By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's
  pull, the pull is not actually cancelled but removed from internal tracking,
  making it impossible for the owning user to stop it
summary: >-
  By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's
  pull, the pull is not actually cancelled but removed from internal tracking,
  making it impossible for the owning user to stop it. Ongoing pulls cannot be
  stopped.
severity: low
cvss: 3.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-862
vendor: Red Hat
product: flatpak
affected:
  - flatpak (all versions)
  - flatpak (all versions)
  - flatpak (all versions)
  - flatpak (all versions)
published: '2026-09-27'
updated: '2026-09-27'
sourceUpdated: '2026-09-27T23:17:01.037'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96283'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-96283'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2539424'
    label: secalert@redhat.com
  - url: 'https://github.com/flatpak/flatpak/security/advisories/GHSA-89xm-3m96-w3jg'
    label: secalert@redhat.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-27T22:59:18.878Z'
---

## Overview

By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to stop it. Ongoing pulls cannot be stopped.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
