CVE-2026-86320
Last modified
CVE-2026-86320 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on the host during the build process, resulting in arbitrary code execution with the privileges of the user running flatpak-builder..
Description
A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on the host during the build process, resulting in arbitrary code execution with the privileges of the user running flatpak-builder.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | All versions |
| Red Hat | Red Hat Enterprise Linux 8 | All versions |
| Red Hat | Red Hat Enterprise Linux 9 | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-86320?
How severe is CVE-2026-86320?
How do I fix CVE-2026-86320?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-86314Integer overflow in the source-bounds check in Memory::init(…6.2
- CVE-2026-86315An out-of-bounds write caused by numeric truncation Samsung…6.2
- CVE-2026-86317A vulnerability was detected in ggml-org llama.cpp up to 0.4…5.3
- CVE-2026-86318A flaw has been found in java-json-tools json-patch up to 1.…5.3
- CVE-2026-86319A vulnerability has been found in java-json-tools json-patch…5.3
- CVE-2026-8632A potential security vulnerability has been identified in th…7.8
- CVE-2026-86321A vulnerability was found in java-json-tools jackson-coreuti…5.3
- CVE-2026-8633IBM Web Server Plug-ins for WebSphere Application Server and…9.8
- CVE-2026-86332A flaw was found in odh-dashboard in Red Hat OpenShift AI. T…6.5
- CVE-2026-86338Ash field_policies are documented to protect against filter-…6
- CVE-2026-8634Crabbox prior to v0.12.0 contains an environment variable ex…9.3
- CVE-2026-86341GitLab has remediated an issue in GitLab EE affecting all ve…4.4
Are you affected by CVE-2026-86320?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
