CVE-2026-34078: Flatpak
Critical severity, CVSS 10.0. EPSS: 0.9% chance of exploitation in the next 30 days.
Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4.
Affected products
- Flatpak Flatpak: up to and including 1.16.3
Published 2026-04-07. Last modified 2026-07-24.