Missing Authorization in PackageKit - #VU147252
Published: September 7, 2026
Vulnerability details
The vulnerability allows a local user to cancel pending offline updates.
The vulnerability exists due to missing authorization in the packagekitd offline-update Trigger method when handling an unset action on the system bus. A local user can call the method with the unset action to cancel pending offline updates.
An administrator-authorized offline update must already be armed.