CVE-2026-76925EPSS p0.9%
CVE-2026-76925CVE-2026-76925
Description
A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatpak.SystemHelper` component. This vulnerability occurs because a privileged `chmod` operation executes before the OSTree repository validation within the `Deploy()` function. An attacker can exploit this timing window to redirect symlinks to arbitrary files, potentially leading to unauthorized file manipulation or information disclosure.
Scoring
| CVSS | 5.8 () |
| Vector | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L |
| EPSS | 0.10% probability of exploitation · percentile 0.9% · 2026-10-01T12:00:22Z |
| Last modified | 2026-09-08 |