CVE-2026-34078

CRITICAL

Flatpak <1.16.4 sandbox-expose Symlinks - Sandbox Escape

Title source: manual
STIX 2.1

Description

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4.

Scores

CVSS v3 10.0
EPSS 0.0168
EPSS Percentile 74.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-59 CWE-61
Status published
Products (2)
flatpak/flatpak < 1.16.3
flatpak/flatpak < 1.16.4
Published Apr 07, 2026
Tracked Since Apr 08, 2026