Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41651

40
FAUCET Score

OVERVIEW CVE-2026-41651 is a time-of-check time-of-use (TOCTOU) race condition vulnerability affecting PackageKit versions 1.0.2 through 1.3.4. PackageKit is a D-Bus abstraction layer used across Linux distributions for package management. The vulnerability allows unprivileged local users to install arbitrary RPM packages with root privileges by exploiting a race condition in transaction flag handling, leading to local privilege escalation. The issue stems from three distinct bugs in the transaction processing code that allow flag overwrites during active transactions and delayed flag validation. PackageKit has addressed this vulnerability in version 1.3.5. SEVERITY This vulnerability carries a CVSS v3.1 score of 8.8 (HIGH) with a local attack vector requiring low complexity and no user interaction. The threat model requires low privileges and affects the confidentiality, integrity, and availability of the system. An attacker can exploit this flaw to execute arbitrary RPM scriptlets as root without authentication, providing complete system compromise capabilities. The vulnerability is particularly concerning because it requires no special conditions beyond local access and minimal complexity to execute. EXPLOITATION STATUS There is currently no evidence of active exploitation in the wild. No CVE Entry (KEV) designation has been assigned, and the vulnerability does not appear on industry hot lists. The EPSS score of 0.000250 indicates minimal current exploitation probability. However, given the high severity rating and straightforward nature of the attack requiring only local access, organizations should prioritize patching before public exploit code becomes widely available.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.2, < 1.3.5CPE matchmatch criteria
cpe:2.3:a:packagekit_project:packagekit:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.0
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.46%
Probability of exploitation in next 30 days
EPSS Percentile
37.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0046 is in the 78th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryvendor investigatingvia nvd_reference
View patch

References

access.redhat.com / errata/RHSA-2026:11504
access.redhat.com / errata/RHSA-2026:11635
access.redhat.com / errata/RHSA-2026:17558
access.redhat.com / errata/RHSA-2026:17560
access.redhat.com / errata/RHSA-2026:17561
access.redhat.com / errata/RHSA-2026:18024
access.redhat.com / errata/RHSA-2026:18031
access.redhat.com / errata/RHSA-2026:18036
access.redhat.com / errata/RHSA-2026:19141
access.redhat.com / errata/RHSA-2026:19354
access.redhat.com / errata/RHSA-2026:19454
access.redhat.com / errata/RHSA-2026:19601
access.redhat.com / errata/RHSA-2026:22146
access.redhat.com / security/cve/CVE-2026-41651
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-41651.json
openwall.com / lists/oss-security/2026/04/22/6
Mailing ListPatchThird Party Advisory
github.com / PackageKit/PackageKit/blob/04057883189efa225a7c785591aa87cb299782f8/src/pk-transaction.c
Product
github.com / PackageKit/PackageKit/blob/04057883189efa225a7c785591aa87cb299782f8/src/pk-transaction.c
Product
github.com / PackageKit/PackageKit/blob/04057883189efa225a7c785591aa87cb299782f8/src/pk-transaction.c
Product
github.com / PackageKit/PackageKit/security/advisories/GHSA-f55j-vvr9-69xv
ExploitVendor Advisory
github.security.telekom.com / 2026/04/pack2theroot-linux-local-privilege-escalation.html
ExploitThird Party Advisory