CVE-2026-76925

A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatpak.SystemHelper` component. This vulnerability occurs because a privileged `chmod` operation executes before the OSTree repository validation within the `Deploy()` function. An attacker can exploit this timing window to redirect symlinks to arbitrary files, potentially leading to unauthorized file manipulation or information disclosure.

Scoring

Severity
MEDIUM
CVSS base score
5.8
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L
EPSS probability
0.10%
CWE
CWE-367
Published
2026-09-04
Last modified
2026-09-08

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs