Junglewise Threat Intelligence

CVE-2026-19816: PackageKit authorization bypass in dnf5 backend

CVE-2026-19816 · Severity: high · CVSS 7.1 · Published 2026-09-14

Technologies: PackageKit. Vendors: PackageKit.

Executive brief

PackageKit is a cross-platform package management system that controls how software updates are installed on Linux systems. A flaw allows unprivileged local users to bypass security checks and permanently uninstall packages by fraudulently claiming to perform a test run, potentially disrupting system stability or removing critical software needed for business operations.

Technical details

PackageKit skips polkit authorization checks for transactions marked with the SIMULATE (dry-run) flag. However, in the dnf5 backend, the RepoRemove handler contains a logic error in its guard condition (role == REPO_REMOVE || !SIMULATE), which evaluates to true regardless of the SIMULATE flag. This allows an unprivileged local attacker to execute genuine package removals while claiming to simulate them, bypassing intended authorization controls. The vulnerability is specific to systems running PackageKit with the dnf5 backend and requires local access to the system.

Affected products

  • PackageKit PackageKit affected versions unknown

Timeline

  • 2026-09-14: disclosed

References

Related threats