Missing Authorization in PackageKit - #VU147252

 

Missing Authorization in PackageKit - #VU147252

Published: September 7, 2026


Vulnerability identifier: #VU147252
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cancel pending offline updates.

The vulnerability exists due to missing authorization in the packagekitd offline-update Trigger method when handling an unset action on the system bus. A local user can call the method with the unset action to cancel pending offline updates.

An administrator-authorized offline update must already be armed.


Affected software

PackageKit

Remediation

Install security update from vendor's website.

PackageKit - update to 1.4.0

External References

Related Security Bulletins