OVERVIEW CVE-2026-34079 is a path traversal vulnerability in Flatpak versions prior to 1.16.4, a widely used Linux application sandboxing framework. The flaw exists in the ld.so caching mechanism, which fails to properly validate that outdated cache file paths are actually located within the designated cache directory before deletion. This insufficient validation allows malicious Flatpak applications to bypass sandbox restrictions and delete arbitrary files on the host system. SEVERITY The vulnerability carries a CVSS 3.1 score of 7.5 (HIGH) with a network-based attack vector, low complexity, and no privilege or user interaction requirements. While the confidentiality impact is none, the integrity impact is significant, enabling unauthorized file deletion across the host system. The threat is further underscored by the FAUCET risk score of 48.0/100, indicating a moderate-to-high risk profile within the vulnerability ecosystem. EXPLOITATION STATUS There is no evidence of active exploitation at this time. The vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog, and the Exploit Prediction Scoring System (EPSS) probability of 0.0014 suggests minimal real-world exploitation likelihood. However, the moderate risk score indicates the vulnerability warrants attention for remediation, particularly for organizations relying on Flatpak for application isolation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.16.4CPE matchmatch criteria | cpe:2.3:a:flatpak:flatpak:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.