CVE-2026-97025

LOW CVSS 3.1: 3.2 EPSS 0.12%
Updated Sep 29, 2026
Fedora
Parameter Value
CVSS 3.2 (LOW)
Type CWE-378
Vendor Fedora
Public PoC No

Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cache directory, allowing other local users on a multi-user system to read the token and impersonate the authenticated user against the OCI repository. Only OCI-based sources (e.g. as used by Fedora) are affected; libostree-based sources such as Flathub are not.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products

red hat:red hat enterprise linux 9 red hat:red hat enterprise linux 10 red hat:red hat enterprise linux 8 red hat:red hat enterprise linux 7