CVE detail
CVE-2026-34078
Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 19.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
20 source links · newest first
- Tails 7.6.2 patches vulnerability that could expose saved filesHelp Net Security
The Tails Project released Tails v7.6.2, an emergency release of the popular open source secure portable operating system. What is Tails? Tails, which is based on Debian GNU/Linux, is aimed at users who want to preserve their online privacy and anonymity. The OS is installed on a dedicated USB stick and when plugged into a computer, it allows users to read and edit documents and images, watch videos, brows the web via the Tor internet … More →
newswww.helpnetsecurity.comApr 16, 2026, 10:31 AM Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Cloudflare moves up its post-quantum deadline as researchers narrow the path to Q-Day Cloudflare announced it is targeting 2029 to complete post-quantum security across its entire product suite, including post-quantum authentication. The company is following a revised roadmap that Google also adopted after announcing that it had improved the quantum algorithm used to break elliptic curve cryptography. Google stopped short … More →
newswww.helpnetsecurity.comApr 12, 2026, 8:00 AM- Flatpak 1.16.4 fixes sandbox escape and three other security flawsHelp Net Security
Flatpak, a Linux application sandboxing and distribution framework, released version 1.16.4, patching four security vulnerabilities. The most severe fix addresses a complete sandbox escape that leads to host file access and code execution in the host context, tracked as CVE-2026-34078. File system exposure Two additional fixes address file system exposure on the host. CVE-2026-34079 prevents arbitrary file deletion on the host filesystem. GHSA-2fxp-43j9-pwvc prevents arbitrary read-access to files in the system-helper context. The fourth fix, … More →
newswww.helpnetsecurity.comApr 8, 2026, 8:32 AM - https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34078.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comApr 7, 2026, 10:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2456276bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comApr 7, 2026, 10:16 PM - https://access.redhat.com/security/cve/CVE-2026-34078access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 7, 2026, 10:16 PM - https://access.redhat.com/errata/RHSA-2026:35843access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 7, 2026, 10:16 PM - https://access.redhat.com/errata/RHSA-2026:30901access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 7, 2026, 10:16 PM - https://access.redhat.com/errata/RHSA-2026:25381access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 7, 2026, 10:16 PM - https://access.redhat.com/errata/RHSA-2026:25068access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 7, 2026, 10:16 PM - https://access.redhat.com/errata/RHSA-2026:23420access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 7, 2026, 10:16 PM - https://access.redhat.com/errata/RHSA-2026:23419access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 7, 2026, 10:16 PM - https://access.redhat.com/errata/RHSA-2026:23418access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 7, 2026, 10:16 PM - https://access.redhat.com/errata/RHSA-2026:23417access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 7, 2026, 10:16 PM - https://access.redhat.com/errata/RHSA-2026:21757access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 7, 2026, 10:16 PM - https://access.redhat.com/errata/RHSA-2026:21756access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 7, 2026, 10:16 PM - https://access.redhat.com/errata/RHSA-2026:21755access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 7, 2026, 10:16 PM - http://www.openwall.com/lists/oss-security/2026/04/10/14www.openwall.com
No excerpt available.
Exploitwww.openwall.comApr 7, 2026, 10:16 PM - http://www.openwall.com/lists/oss-security/2026/04/09/8www.openwall.com
No excerpt available.
Exploitwww.openwall.comApr 7, 2026, 10:16 PM No excerpt available.
Exploitgithub.comApr 7, 2026, 10:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-17459CVSS 2.1 · Low
A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/Extern…
- CVE-2026-14699CVSS 4.8 · Medium
A weakness has been identified in zcaceres markdownify-mcp up to 1.1.0. The affected element is the function assertPathAllowed of the file src/Markdownify.ts. Executing a manipula…
- CVE-2026-52811CVSS 9.0 · Critical
Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only on the leaf of the upload target (osx.IsSymlink(targetPath)…
- CVE-2026-8784CVSS 1.8 · Low
A vulnerability was detected in npitre cramfs-tools up to 2.2. Affected is the function change_file_status of the file cramfsck.c. Performing a manipulation results in symlink fol…
- CVE-2026-7832CVSS 6.4 · Medium
A security flaw has been discovered in IObit Advanced SystemCare 19. This affects an unknown part of the file ASC.exe of the component Service. The manipulation results in symlink…
- CVE-2026-7397CVSS 1.9 · Low
A security flaw has been discovered in NousResearch hermes-agent 0.8.0. This affects the function _check_sensitive_path of the file tools/file_tools.py. The manipulation results i…