CVE-2026-76925
Last modified
CVE-2026-76925 is a medium-severity vulnerability rated 5.8/10 on the CVSS scale. A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatpak.SystemHelper` component. EPSS estimates a 0.10% chance of exploitation in the next 30 days.
Description
A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatpak.SystemHelper` component. This vulnerability occurs because a privileged `chmod` operation executes before the OSTree repository validation within the `Deploy()` function. An attacker can exploit this timing window to redirect symlinks to arbitrary files, potentially leading to unauthorized file manipulation or information disclosure.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | All versions |
| Red Hat | Red Hat Enterprise Linux 7 | All versions |
| Red Hat | Red Hat Enterprise Linux 8 | All versions |
| Red Hat | Red Hat Enterprise Linux 9 | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-76925?
How severe is CVE-2026-76925?
How do I fix CVE-2026-76925?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-7692A vulnerability was detected in Wavlink WL-WN570HA1 R70HA1 V…6.3
- CVE-2026-769203gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0…5.5
- CVE-2026-76921CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to …5.5
- CVE-2026-76922Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.…5.5
- CVE-2026-76923Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4…5.5
- CVE-2026-76924Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.…5.5
- CVE-2026-76926BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.…6.5
- CVE-2026-76927H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 t…7.5
- CVE-2026-76928X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0…7.5
- CVE-2026-76929Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.…5.5
- CVE-2026-7693The Backup Migration plugin for WordPress is vulnerable to O…7.2
- CVE-2026-76931The Zephyr Project Manager plugin for WordPress is vulnerabl…6.4
Are you affected by CVE-2026-76925?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
