CVE-2026-92162 is a path-traversal vulnerability in Flatpak's DeployAppstream handling, affecting Flatpak 1.18.0 and earlier. The privileged flatpak-system-helper did not sufficiently validate architecture-name arguments. A crafted architecture value can traverse outside the intended deployment root and cause the helper to create a root-owned directory tree whose contents are influenced by a configured OCI remote, along with a root-owned lock file and icons directory, at unintended filesystem locations.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This three-file repository contains an educational but functional local privilege-escalation proof of concept for the claimed CVE-2026-92162 in Flatpak's flatpak-system-helper. The main entry point, poc_arch_traversal.sh, is a Bash script with embedded Python/Gio D-Bus clients. It calls DeployAppstream using an unvalidated arch value of ../../../../../root/.ssh. The stated vulnerable behavior is that the root helper incorporates arch into an appstream filesystem path and creates parent directories before attempting an OCI registry fetch, allowing lexical traversal outside the intended tree. Default test mode builds an isolated environment: it creates a temporary system directory and OSTree repository, launches dbus-daemon with a permissive private session-bus configuration, starts the helper with --session, configures an OCI remote pointing to 127.0.0.1:19876, and verifies that the escaped directory appears beneath the temporary work directory. Production mode discovers a system OCI remote via flatpak remotes --system or accepts one explicitly, then issues the DeployAppstream call over the system bus. It does not use sudo itself, but relies on the reported allow_active polkit policy for an active local session; it instructs the operator to verify /root/.ssh afterward. requirements.txt is documentation only and lists required system packages (Flatpak, OSTree, D-Bus, gdbus, and Python GI bindings). README.md documents setup, the claimed vulnerability chain context, mitigation through architecture-name validation, and cleanup. The PoC is operational rather than framework-based: its traversal payload and output directory are hardcoded, and it primarily demonstrates privileged directory creation rather than directly writing a payload or obtaining a shell.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A medium-severity Flatpak path-handling flaw in flatpak-system-helper affecting systems configured with an OCI remote. A local authenticated user can supply a crafted architecture name to cause creation of root-owned files and directories outside the intended root. In combination with other flaws fixed in Flatpak 1.18.1, it can enable local root privilege escalation.
A critical, network-reachable vulnerability identified as CVE-2026-92162, affecting Debian Linux 12.0 and Flatpak according to the supplied Nessus plugin metadata. It requires no privileges or user interaction and can result in high confidentiality, integrity, and availability impact.
A Flatpak path-traversal vulnerability caused by an unvalidated architecture parameter in DeployAppstream.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.