https://seclists.org/oss-sec/2026/q2/56: 4 security fixes in Flatpak, including critical CVE-2026-34078: Complete sandbox escape leading to host file access and code execution in the host context
Published Apr 9, 2026
·Updated
Affected Software
1 affected component
Flatpak Flatpak<1.16.4
Frequently Asked Questions
1
What is the severity of CVE-2026-34078?
CVE-2026-34078 has been classified as a critical severity vulnerability.
2
What does CVE-2026-34078 exploit?
CVE-2026-34078 is a complete sandbox escape vulnerability that allows unauthorized access to host files and code execution in the host context.
3
How do I fix CVE-2026-34078?
To mitigate CVE-2026-34078, update to Flatpak version 1.16.4 or 1.17.4.
4
What versions of Flatpak include the fix for CVE-2026-34078?
Flatpak versions 1.16.4 and 1.17.4 include the security fix for CVE-2026-34078.
5
Are there any known regressions caused by the fixes for CVE-2026-34078?
Yes, Flatpak versions 1.16.5 and 1.17.5 were released to address regressions caused by the critical security fix.