PatchSiren cyber security CVE debrief
CVE-2026-96279 Red Hat CVE debrief
CVE-2026-96279 debrief based on CVE Program and NVD records. The vulnerability allows a malicious OCI registry to hardlink arbitrary host files into the extraction directory during Flatpak application installations or updates, potentially disclosing sensitive host file contents. System administrators and security teams should assess exposure, especially for system-wide installs running as root, and verify host file permissions. This issue is particularly concerning for system-wide installs as it can lead to the disclosure of sensitive files such as /etc/shadow.
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-27
- Original CVE updated
- 2026-09-27
- Advisory published
- 2026-09-27
- Advisory updated
- 2026-09-27
Who should care
System administrators and security teams responsible for Flatpak installations, especially those running system-wide installs as root, should assess exposure and verify host file permissions
Why it matters
CVE-2026-96279 allows a malicious OCI registry to disclose arbitrary host file contents via hardlinks during Flatpak application installations or updates, posing a risk to system-wide installs running as root.
- Potential disclosure of sensitive host file contents, including /etc/shadow for system-wide installs running as root
- Need to verify host file permissions and restrict access to sensitive files
- Potential for malicious OCI registry interactions to lead to unauthorized file access
- Requires assessment of Flatpak installation exposure and monitoring of application installations and updates
Technical summary
A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from an OCI remote, allowing disclosure of arbitrary host file contents. For system-wide installs running as root, this includes sensitive files such as /etc/shadow. The vulnerability is particularly concerning for system-wide installs as it can lead to the disclosure of sensitive files. Defenders should assess exposure and verify host file permissions to mitigate potential risks.
Defensive priority
Assess exposure of Flatpak installations, especially system-wide installs running as root, and verify host file permissions
Recommended defensive actions
- Assess exposure of Flatpak installations, especially system-wide installs running as root
- Verify host file permissions and restrict access to sensitive files
- Monitor Flatpak application installations and updates for suspicious activity
- Consider implementing additional security controls for OCI registry interactions
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
CVE Program and NVD records indicate a malicious OCI registry can disclose arbitrary host file contents via hardlinks during Flatpak application installation or updates. Evidence is limited to CVE Program and NVD records, which suggest that the vulnerability is exploitable and could lead to unauthorized file access. Defenders should verify host file permissions and assess exposure of Flatpak installations, especially those running as root.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-96279 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-96279
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-96279 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-96279
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-96279
-
Source reference
Unverified legacy reference
URL: https://github.com/flatpak/flatpak/security/advisories/GHSA-9rww-v4mm-x4jg
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.