Description
A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role == REPO_REMOVE || !SIMULATE), which is always true for RepoRemove. An unprivileged local user can therefore perform a genuine package uninstall while claiming to simulate. This vulnerability only affects systems using PackageKit with the dnf5 backend.
Published: 2026-09-14
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized package removal leading to system integrity compromise
Action: Assess Impact
AI Analysis

Impact

A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry‑run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role == REPO_REMOVE || !SIMULATE), which is always true for RepoRemove. An unprivileged local user can therefore perform a genuine package uninstall while claiming to simulate. This vulnerability only affects systems using PackageKit with the dnf5 backend.

Affected Systems

Affected systems include Fedora and Red Hat Enterprise Linux 10, 6, 7, 8, and 9 running PackageKit with the dnf5 backend.

Risk and Exploitability

The flaw carries a CVSS score of 7.1, indicating a high severity. EPSS data indicates a low exploitation probability of < 1% (0.00143), and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is local and does not require privileged access prior to execution, so exploit this by invoking package removal commands. Given the lack of an official patch or workaround, the risk remains significant for affected installations.

Generated by OpenCVE AI on September 20, 2026 at 22:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for an updated PackageKit release that fixes the SIMULATE flag handling in the dnf5 backend
  • If an update is not yet available, disable the dnf5 backend or remove the affected repository configuration so that RepoRemove operations are prevented from performing real removals
  • Enforce strict polkit policies to require authentication for package removal operations and monitor system logs for unauthorized removal attempts

Generated by OpenCVE AI on September 20, 2026 at 22:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in PackageKit. In the dnf5 backend, the RepoRemove handler ignores the SIMULATE transaction flag and executes a real package removal, allowing an unprivileged local user to uninstall packages without polkit authorization. A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role == REPO_REMOVE || !SIMULATE), which is always true for RepoRemove. An unprivileged local user can therefore perform a genuine package uninstall while claiming to simulate. This vulnerability only affects systems using PackageKit with the dnf5 backend.
Title packagekit: PackageKit: PackageKit dnf5 ignores SIMULATE on RepoRemove PackageKit: dnf5 backend ignores SIMULATE on RepoRemove
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References

Thu, 10 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Packagekit
Packagekit packagekit
Vendors & Products Packagekit
Packagekit packagekit

Thu, 10 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in PackageKit. In the dnf5 backend, the RepoRemove handler ignores the SIMULATE transaction flag and executes a real package removal, allowing an unprivileged local user to uninstall packages without polkit authorization.
Title packagekit: PackageKit: PackageKit dnf5 ignores SIMULATE on RepoRemove
Weaknesses CWE-863
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

threat_severity

Important


Subscriptions

Packagekit Packagekit
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2026-09-15T18:04:51.167Z

Reserved: 2026-08-14T02:40:21.336Z

Link: CVE-2026-19816

cve-icon Vulnrichment

Updated: 2026-09-15T17:38:42.894Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T20:16:43.760

Modified: 2026-09-18T19:34:36.657

Link: CVE-2026-19816

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-09T19:36:39Z

Links: CVE-2026-19816 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:15:05Z

Weaknesses