Incorrect authorization in PackageKit - CVE-2026-19816

 

Incorrect authorization in PackageKit - CVE-2026-19816

Published: September 10, 2026


Vulnerability identifier: #VU148896
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-19816
CWE-ID: CWE-863
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to remove installed packages.

The vulnerability exists due to incorrect authorization in the dnf5 backend RepoRemove handler when processing RepoRemove transactions with the SIMULATE flag. A local user can invoke RepoRemove with the SIMULATE flag to remove installed packages.

Only systems using the PackageKit dnf5 backend are affected. Setting autoremove to true can remove packages installed from the specified repository and sibling repository IDs sharing the same repository file.


Affected software

PackageKit
Fedora
PackageKit

How to mitigate CVE-2026-19816

Install security update from vendor's website.

PackageKit - update to 1.4.0
PackageKit - addressed in versions 1.4.0-1.fc44, 1.4.0-1.fc45

External References

Related Security Bulletins