CVE WATCH / VULNERABILITY DETAIL

CVE-2026-97026

LOWCVSS 3.9NVD feed

Published 28 September 2026 · tracked since 29 September 2026

Description

Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems with a permissive umask, other local users could read or modify the temporary directory used while installing apps or runtimes, potentially causing installation f

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-97026 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-97026

LOWCVSS 3.9NVD feed

Published 28 September 2026 · tracked since 29 September 2026

Description

Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems with a permissive umask, other local users could read or modify the temporary directory used while installing apps or runtimes, potentially causing installation f

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]