A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role == REPO_REMOVE || !SIMULATE), which is always true for RepoRemove. An unprivileged local user can therefore perform a genuine package uninstall while claiming to simulate. This vulnerability only affects systems using PackageKit with the dnf5 backend.

Project Subscriptions

Vendors Products
Packagekit Subscribe
Packagekit Subscribe
Enterprise Linux Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in PackageKit. In the dnf5 backend, the RepoRemove handler ignores the SIMULATE transaction flag and executes a real package removal, allowing an unprivileged local user to uninstall packages without polkit authorization. A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role == REPO_REMOVE || !SIMULATE), which is always true for RepoRemove. An unprivileged local user can therefore perform a genuine package uninstall while claiming to simulate. This vulnerability only affects systems using PackageKit with the dnf5 backend.
Title packagekit: PackageKit: PackageKit dnf5 ignores SIMULATE on RepoRemove PackageKit: dnf5 backend ignores SIMULATE on RepoRemove
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References

Thu, 10 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Packagekit
Packagekit packagekit
Vendors & Products Packagekit
Packagekit packagekit

Thu, 10 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in PackageKit. In the dnf5 backend, the RepoRemove handler ignores the SIMULATE transaction flag and executes a real package removal, allowing an unprivileged local user to uninstall packages without polkit authorization.
Title packagekit: PackageKit: PackageKit dnf5 ignores SIMULATE on RepoRemove
Weaknesses CWE-863
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

threat_severity

Important


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2026-09-15T18:04:51.167Z

Reserved: 2026-08-14T02:40:21.336Z

Link: CVE-2026-19816

cve-icon Vulnrichment

Updated: 2026-09-15T17:38:42.894Z

cve-icon NVD

Status : Received

Published: 2026-09-14T20:16:43.760

Modified: 2026-09-15T19:17:18.107

Link: CVE-2026-19816

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-09T19:36:39Z

Links: CVE-2026-19816 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T14:00:11Z

Weaknesses