CVE-2026-96284: Red Hat Enterprise Linux 10

Low severity, CVSS 2.5. EPSS: 0.1% chance of exploitation in the next 30 days.

A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the system helper follow symlinks when importing OCI images that are under the user's control.

Affected products

Published 2026-09-27. Last modified 2026-09-29.