Back

LOW

Flatpak: flatpak: world-readable oci authentication token in system-helper cache path

Published Sep 28, 2026

Description

Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cache directory, allowing other local users on a multi-user system to read the token and impersonate the authenticated user against the OCI repository. Only OCI-based sources (e.g. as used by Fedora) are affected; libostree-based sources such as Flathub are not.

Affected products

Remediation

Vendor solution

Use libostree repositories such as Flathub, or unauthenticated (public) OCI repositories.

Red Hat statement

Red Hat estimates the CVSSv3.1 vector of CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N from provided CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N. This attack requires user interaction and breaches confidentiality outside of its original scope.

Red Hat mitigation

Use libostree repositories such as Flathub, or unauthenticated (public) OCI repositories.

Metrics

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 28, 2026
Updated Sep 29, 2026
Reserved Sep 23, 2026
CISA Vulnrichment
Updated Sep 29, 2026
NVD
Status Received
Modified Sep 28, 2026
Red Hat
Severity Low
Public date Sep 28, 2026