CVE-2026-96281

MEDIUM CVSS 3.1: 6.2
Updated Sep 28, 2026
Red Hat
Parameter Value
CVSS 6.2 (MEDIUM)
Type CWE-284 (Improper Access Control)
Vendor Red Hat
Public PoC No

On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the anti-downgrade check to fail to find a reference date. A malicious local user could use this to expose other users of the same system to an app version with unfixed vulnerabilities.

Attack Parameters

Attack Vector
Physical
Requires physical access
Attack Complexity
High
Difficult to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products

red hat:red hat enterprise linux 7 red hat:red hat enterprise linux 9 red hat:red hat enterprise linux 10 red hat:red hat enterprise linux 8