Back

MEDIUM

Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system apps/runtimes

Published Sep 27, 2026

Description

On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the anti-downgrade check to fail to find a reference date. A malicious local user could use this to expose other users of the same system to an app version with unfixed vulnerabilities.

Affected products

Remediation

Vendor solution

Ensure that Flatpak apps installed system-wide are fully updated before running them.

Metrics

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 27, 2026
Updated Sep 30, 2026
Reserved Sep 22, 2026
CISA Vulnrichment
Updated Sep 30, 2026
NVD
Status Received
Modified Sep 27, 2026
Red Hat
Severity n/a
Public date n/a