Description
A vulnerability has been found in PackageKit up to 1.3.5. Affected is the function g_file_test of the file src/pk-transaction.c of the component API. Such manipulation of the argument frontend-socket leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Problem types
Incorrect Privilege Assignment
Timeline
| 2026-05-31: | Advisory disclosed |
| 2026-05-31: | VulDB entry created |
| 2026-05-31: | VulDB entry last update |
Credits
Rosa Yu (VulDB User)
References
vuldb.com/vuln/367587 (VDB-367587 | PackageKit API pk-transaction.c g_file_test improper authorization)
vuldb.com/vuln/367587/cti (VDB-367587 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/cve/CVE-2026-10294 (CVE-2026-10294 | CVE Analysis and Report)
vuldb.com/submit/826470 (Submit #826470 | PackageKit v1.3.5 Incorrect Use of Privileged APIs)
github.com/PackageKit/PackageKit/issues/969
github.com/PackageKit/PackageKit/