Red HatCVE-2026-96283
Red Hat Enterprise Linux: missing authorization
Low3.3CVE-2026-96283 · Published Sep 27, 2026
By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to stop it. Ongoing pulls cannot be stopped.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Enterprise Linux 10 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 7 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 8 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 9 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-862
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 27 | Red Hat Enterprise Linux: link following | Low2.5 | No fix yet |
| Sep 27 | Red Hat Enterprise Linux: link following | Low3.1 | No fix yet |
| Sep 27 | Red Hat Enterprise Linux: code execution | High7.5 | No fix yet |
| Sep 27 | Red Hat Enterprise Linux: improper access control | Medium6.2 | No fix yet |
| Sep 27 | Red Hat Enterprise Linux: link following | Medium6.5 | No fix yet |
| Sep 25 | Red Hat QEMU: use after free | High8.8 | No fix yet |