Red HatCVE-2026-96282
Red Hat Enterprise Linux: link following
Low3.1CVE-2026-96282 · Published Sep 27, 2026
A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host directory listings can be disclosed to sandboxed applications using the extension. Additionally, unvalidated extension metadata can cause extension content to be mounted at unintended locations inside the sandbox.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Enterprise Linux 10 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 7 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 8 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 9 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-59
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 27 | Red Hat Enterprise Linux: link following | Low2.5 | No fix yet |
| Sep 27 | Red Hat Enterprise Linux: missing authorization | Low3.3 | No fix yet |
| Sep 27 | Red Hat Enterprise Linux: code execution | High7.5 | No fix yet |
| Sep 27 | Red Hat Enterprise Linux: improper access control | Medium6.2 | No fix yet |
| Sep 27 | Red Hat Enterprise Linux: link following | Medium6.5 | No fix yet |
| Sep 25 | Red Hat QEMU: use after free | High8.8 | No fix yet |