CVE-2026-34078

Publication date 7 April 2026

Last updated 30 June 2026


Ubuntu priority

Cvss 3 Severity Score

9.0 · Critical

Score breakdown

Description

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4.

Status

Package Ubuntu Release Status
flatpak 26.04 LTS resolute
Not affected
25.10 questing Ignored end of life, was needs-triage
24.04 LTS noble
Vulnerable
22.04 LTS jammy
Vulnerable
20.04 LTS focal
Vulnerable
18.04 LTS bionic
Vulnerable

Severity score breakdown

CVSS version:

Base score 9.3 · Critical

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Base score 9.0 · Critical

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H


Access our resources on patching vulnerabilities