Incorrect authorization in PackageKit - CVE-2026-19816
Published: September 10, 2026
Vulnerability details
The vulnerability allows a local user to remove installed packages.
The vulnerability exists due to incorrect authorization in the dnf5 backend RepoRemove handler when processing RepoRemove transactions with the SIMULATE flag. A local user can invoke RepoRemove with the SIMULATE flag to remove installed packages.
Only systems using the PackageKit dnf5 backend are affected. Setting autoremove to true can remove packages installed from the specified repository and sibling repository IDs sharing the same repository file.
Affected software
Fedora
PackageKit
How to mitigate CVE-2026-19816
PackageKit - addressed in versions 1.4.0-1.fc44, 1.4.0-1.fc45