{"affected":[{"affectedData":[{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:10"],"defaultStatus":"unknown","packageName":"flatpak","product":"Red Hat Enterprise Linux 10","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:7"],"defaultStatus":"unknown","packageName":"flatpak","product":"Red Hat Enterprise Linux 7","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:8"],"defaultStatus":"unknown","packageName":"flatpak","product":"Red Hat Enterprise Linux 8","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:9"],"defaultStatus":"unknown","packageName":"flatpak","product":"Red Hat Enterprise Linux 9","vendor":"Red Hat"}],"source":"secalert@redhat.com"}],"cveTags":[],"descriptions":[{"lang":"en","value":"If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extension` with that SDK, attacker-chosen files could be written outside the working directory, since the target path is resolved via a function that allows `..` traversal."}],"id":"CVE-2026-96276","lastModified":"2026-09-23T19:40:10.000","metrics":{"cvssMetricV31":[{"cvssData":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"exploitabilityScore":3.9,"impactScore":5.9,"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"id":"CVE-2026-96276","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","timestamp":"2026-09-23T15:28:10.393280Z","version":"2.0.3"}}]},"published":"2026-09-23T15:17:32.317","references":[{"source":"secalert@redhat.com","url":"https://access.redhat.com/security/cve/CVE-2026-96276"},{"source":"secalert@redhat.com","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2539418"},{"source":"secalert@redhat.com","url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-8qxj-x646-phcm"}],"sourceIdentifier":"secalert@redhat.com","vulnStatus":"Awaiting Analysis","weaknesses":[{"description":[{"lang":"en","value":"CWE-22"}],"source":"secalert@redhat.com","type":"Secondary"}]}