CVE-2026-34078

Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
07/04/2026
Last modified:
24/04/2026

Description

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:flatpak:flatpak:*:*:*:*:*:*:*:* 1.16.3 (including)