Missing Authorization in PackageKit - CVE-2026-55752
Published: September 10, 2026
Vulnerability details
The vulnerability allows a local user to execute arbitrary code with root privileges.
The vulnerability exists due to missing authorization in the alpm install_files_thread handler when processing install-file transactions with the only_download flag. A local user can submit a package containing a post-install scriptlet to execute arbitrary code with root privileges.
Exploitation requires a relaxed SigLevel configuration.