CVE-2026-34078
Critical · CVSS 10.0Flatpak — Symlink following sandbox escape leading to arbitrary file access and host code execution
- CVSS
- 10.0
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-61, CWE-59
Description
Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4.
Search profile — drives PoC discovery
Symbols sandbox-exposeflatpak-portalflatpak runGHSA-cc2q-qc34-jprgsandbox_exposeportalsymlinkhost path mount
Keywords CVE-2026-34078Flatpak sandbox escapeFlatpak symlink portalsandbox-expose symlinkFlatpak portal symlink bypassGHSA-cc2q-qc34-jprgFlatpak arbitrary file accessFlatpak 1.16.4 patchCWE-59 FlatpakFlatpak host code execution PoC
Versions: < 1.16.4
References
- https://github.com/flatpak/flatpak/security/advisories/GHSA-cc2q-qc34-jprg
- http://www.openwall.com/lists/oss-security/2026/04/09/8
- http://www.openwall.com/lists/oss-security/2026/04/10/14
- https://access.redhat.com/errata/RHSA-2026:21755
- https://access.redhat.com/errata/RHSA-2026:21756
- https://access.redhat.com/errata/RHSA-2026:21757
- https://access.redhat.com/errata/RHSA-2026:23417
- https://access.redhat.com/errata/RHSA-2026:23418
- https://access.redhat.com/errata/RHSA-2026:23419
- https://access.redhat.com/errata/RHSA-2026:23420
- https://access.redhat.com/errata/RHSA-2026:25068
- https://access.redhat.com/errata/RHSA-2026:25381
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T06:30:14.000Z