---
cve: "CVE-2026-96283"
severity: "LOW"
cvss: 3.3
epss: "0.1%"
vendor: "Generic Security"
kev: false
exploited: false
published: "2026-09-27 22:17:06"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-10-03T17:15:00+02:00"
---

# CVE-2026-96283

> 3.3 LOW · 🧪 PoC

## Beschreibung

By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to stop it. Ongoing pulls cannot be stopped.

## CNA-Record (Kanon, cvelistV5)

- CNA: **redhat**
- State: PUBLISHED
- Stand: 2026-09-28 13:34:26
- CNA-CVSS: **3.3** (`CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L`)

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **no**
  - Technical Impact: **partial**

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Keine | good |
| A Verfügbarkeit | Gering | warn |

## Referenzen

- <https://access.redhat.com/security/cve/CVE-2026-96283>
- <https://bugzilla.redhat.com/show_bug.cgi?id=2539424>
- <https://github.com/flatpak/flatpak/security/advisories/GHSA-89xm-3m96-w3jg>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-96283) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
