CVE-2026-96283

Summary

By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to stop it. Ongoing pulls cannot be stopped.

Affected Software

VendorProductVersion RangeStatus

Weaknesses

  • CWE-862: Missing Authorization

Workarounds

No known mitigation other than updating.

References