Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.0
Red Hat Flatpak Security Update: Unauthorized File Access
RHSA-2026:30901
Summary
A security update has been released for Red Hat Flatpak to fix a vulnerability that could allow an attacker to access files they shouldn't have access to. This update is important for users who rely on Flatpak for application installation and management. To stay secure, apply the latest update as soon as possible.
What to do
- Update redhat flatpak to version 0:1.12.9-2.el8_4.
- Update redhat flatpak-debuginfo to version 0:1.12.9-2.el8_4.
- Update redhat flatpak-debugsource to version 0:1.12.9-2.el8_4.
- Update redhat flatpak-libs to version 0:1.12.9-2.el8_4.
- Update redhat flatpak-libs-debuginfo to version 0:1.12.9-2.el8_4.
- Update redhat flatpak-selinux to version 0:1.12.9-2.el8_4.
- Update redhat flatpak-session-helper to version 0:1.12.9-2.el8_4.
- Update redhat flatpak-session-helper-debuginfo to version 0:1.12.9-2.el8_4.
- Update redhat flatpak-tests-debuginfo to version 0:1.12.9-2.el8_4.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Red Hat:rhel_aus:8.4::appstream | redhat | flatpak |
< 0:1.12.9-2.el8_4 Fix: upgrade to 0:1.12.9-2.el8_4
|
| Red Hat:rhel_aus:8.4::appstream | redhat | flatpak-debuginfo |
< 0:1.12.9-2.el8_4 Fix: upgrade to 0:1.12.9-2.el8_4
|
| Red Hat:rhel_aus:8.4::appstream | redhat | flatpak-debugsource |
< 0:1.12.9-2.el8_4 Fix: upgrade to 0:1.12.9-2.el8_4
|
| Red Hat:rhel_aus:8.4::appstream | redhat | flatpak-libs |
< 0:1.12.9-2.el8_4 Fix: upgrade to 0:1.12.9-2.el8_4
|
| Red Hat:rhel_aus:8.4::appstream | redhat | flatpak-libs-debuginfo |
< 0:1.12.9-2.el8_4 Fix: upgrade to 0:1.12.9-2.el8_4
|
| Red Hat:rhel_aus:8.4::appstream | redhat | flatpak-selinux |
< 0:1.12.9-2.el8_4 Fix: upgrade to 0:1.12.9-2.el8_4
|
| Red Hat:rhel_aus:8.4::appstream | redhat | flatpak-session-helper |
< 0:1.12.9-2.el8_4 Fix: upgrade to 0:1.12.9-2.el8_4
|
| Red Hat:rhel_aus:8.4::appstream | redhat | flatpak-session-helper-debuginfo |
< 0:1.12.9-2.el8_4 Fix: upgrade to 0:1.12.9-2.el8_4
|
| Red Hat:rhel_aus:8.4::appstream | redhat | flatpak-tests-debuginfo |
< 0:1.12.9-2.el8_4 Fix: upgrade to 0:1.12.9-2.el8_4
|
| Red Hat:rhel_eus_long_life:8.4::appstream | redhat | flatpak |
< 0:1.12.9-2.el8_4 Fix: upgrade to 0:1.12.9-2.el8_4
|
| Red Hat:rhel_eus_long_life:8.4::appstream | redhat | flatpak-debuginfo |
< 0:1.12.9-2.el8_4 Fix: upgrade to 0:1.12.9-2.el8_4
|
| Red Hat:rhel_eus_long_life:8.4::appstream | redhat | flatpak-debugsource |
< 0:1.12.9-2.el8_4 Fix: upgrade to 0:1.12.9-2.el8_4
|
| Red Hat:rhel_eus_long_life:8.4::appstream | redhat | flatpak-libs |
< 0:1.12.9-2.el8_4 Fix: upgrade to 0:1.12.9-2.el8_4
|
| Red Hat:rhel_eus_long_life:8.4::appstream | redhat | flatpak-libs-debuginfo |
< 0:1.12.9-2.el8_4 Fix: upgrade to 0:1.12.9-2.el8_4
|
| Red Hat:rhel_eus_long_life:8.4::appstream | redhat | flatpak-selinux |
< 0:1.12.9-2.el8_4 Fix: upgrade to 0:1.12.9-2.el8_4
|
| Red Hat:rhel_eus_long_life:8.4::appstream | redhat | flatpak-session-helper |
< 0:1.12.9-2.el8_4 Fix: upgrade to 0:1.12.9-2.el8_4
|
| Red Hat:rhel_eus_long_life:8.4::appstream | redhat | flatpak-session-helper-debuginfo |
< 0:1.12.9-2.el8_4 Fix: upgrade to 0:1.12.9-2.el8_4
|
| Red Hat:rhel_eus_long_life:8.4::appstream | redhat | flatpak-tests-debuginfo |
< 0:1.12.9-2.el8_4 Fix: upgrade to 0:1.12.9-2.el8_4
|
Original title
Red Hat Security Advisory: flatpak security update
osv CVSS3.1
9.0
- https://access.redhat.com/errata/RHSA-2026:30901 Vendor Advisory
- https://access.redhat.com/security/updates/classification/#important Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2456276 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2456284 Third Party Advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_30901.... Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2026-34078 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-34078 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-34078 Vendor Advisory
- https://github.com/flatpak/flatpak/security/advisories/GHSA-cc2q-qc34-jprg Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-34079 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-34079 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-34079 Vendor Advisory
- https://github.com/flatpak/flatpak/security/advisories/GHSA-p29x-r292-46pp Third Party Advisory
Published: 29 Jun 2026 · Updated: 4 Jul 2026 · First seen: 4 Jul 2026