Sceawere
Vulnerability Detail
CVE-2026-96281UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Flatpak Local Anti-Downgrade Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.2
- Creation Date
- 11h ago
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- Attack Type
- Improper Access Control
- Vector String
- CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the anti-downgrade check to fail to find a reference date. A malicious local user could use this to expose other users of the same system to an app version with unfixed vulnerabilities.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.2",
"pubDate": "2026-09-27T21:17:04.330Z",
"pubdate": "2026-09-27T21:17:04.330Z",
"executiveSummary": "A security vulnerability exists in the Flatpak system-helper component that allows an unprivileged local user to manipulate system-wide application states.\nThe vulnerability involves the improper handling of the RemoveLocalRef method, which can be leveraged to remove application reference metadata.\nBy deleting the remote reference associated with a system-wide Flatpak installation, an attacker can circumvent anti-downgrade mechanisms that rely on reference timestamps to ensure package integrity.\nThis vulnerability is limited to local exploitation, requiring an active session on a multi-user system.\nThe primary risk is the silent transition of a shared application to an older, vulnerable version, effectively re-introducing security flaws that were previously remediated.\nThe attack is characterized as a local privilege escalation or security policy bypass, impacting the confidentiality and integrity of applications shared across multiple system users.",
"technicalDetails": "The root cause of this vulnerability lies in the insufficient authorization and validation logic within the Flatpak system-helper's RemoveLocalRef method. This method is intended to manage local references for Flatpak applications, but it fails to adequately restrict the scope of operation when invoked by unprivileged users on shared systems.\nIn the context of Flatpak’s installation architecture, anti-downgrade checks are essential to prevent the deployment of legacy versions that may contain known security vulnerabilities. These checks typically verify the installation date and version against a stored remote reference. The vulnerability is triggered when a malicious actor invokes the RemoveLocalRef method to delete the metadata associated with a current system-wide application.\nThe attack flow follows these steps: First, the attacker identifies a target Flatpak application installed system-wide. Second, the attacker interacts with the system-helper daemon, leveraging the lack of strict access control on the RemoveLocalRef method to remove the application's associated remote ref. Third, because the system-helper improperly processes this removal, the internal security checks fail to identify the existing reference date during subsequent validation attempts. Finally, the system becomes susceptible to forced or accidental downgrades to older versions which no longer trigger the anti-downgrade protection logic.\nBecause this operation occurs at the system-helper level, the impact is global to all users of the system. An attacker can effectively force an environment where vulnerable software is executed by other users, potentially leading to arbitrary code execution or data exposure within the context of those users' privileges. The vulnerability is strictly local, as it necessitates an active login session and the ability to interact with the Flatpak D-Bus interface. No network exposure is required for the initial exploitation; however, the subsequent impact is the systematic reduction of the security posture of shared applications across the entire multi-user environment."
}