← All Advisories

CVE-2026-96275

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-96275

Key Details

CVECVE-2026-96275
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-09-25
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsRed Hat Red Hat Enterprise Linux 10, Red Hat Red Hat Enterprise Linux 8, Red Hat Red Hat Enterprise Linux 9, and Red Hat Red Hat Enterprise Linux 7
Classified asCWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 7
SubsystemsGeneral OT
SectorsMultiple

What to Know

A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-96275
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-96275