CVE-2026-96283
3.3
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Summary
By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to stop it. Ongoing pulls cannot be stopped.
Affected Software
| Vendor | Product | Version Range | Status |
|---|
Weaknesses
- CWE-862: Missing Authorization
Workarounds
No known mitigation other than updating.
References
- https://access.redhat.com/security/cve/CVE-2026-96283
- https://bugzilla.redhat.com/show_bug.cgi?id=2539424
- https://github.com/flatpak/flatpak/security/advisories/GHSA-89xm-3m96-w3jg
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.