Medium severity6.2NVD Advisory· Published Sep 27, 2026· Updated Sep 27, 2026
CVE-2026-96281
CVE-2026-96281
Description
On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the anti-downgrade check to fail to find a reference date. A malicious local user could use this to expose other users of the same system to an app version with unfixed vulnerabilities.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.