CVE-2026-41651Disclosure(packagekit_project / packagekit)

CRITICALCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 14 mentions and remains active

Immediate actions

  • Patch packagekit_project packagekit systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation. This is patched in version 1.3.5. A local unprivileged user can install arbitrary RPM packages as root, including executing RPM scriptlets, without authentication. The vulnerability is a TOCTOU race condition on `transaction->cached_transaction_flags` combined with a silent state-machine guard that discards illegal backward transitions while leaving corrupted flags in place. Three bugs exist in `src/pk-transaction.c`: 1. Unconditional flag overwrite (line 4036): `InstallFiles()` writes caller-supplied flags to `transaction->cached_transaction_flags` without checking whether the transaction has already been authorized/started. A second call blindly overwrites the flags even while the transaction is RUNNING. 2. Silent state-transition rejection (lines 873–882): `pk_transaction_set_state()` silently discards backward state transitions (e.g. `RUNNING` → `WAITING_FOR_AUTH`) but the flag overwrite at step 1 already happened. The transaction continues running with corrupted flags. 3. Late flag read at execution time (lines 2273–2277): The scheduler's idle callback reads cached_transaction_flags at dispatch time, not at authorization time. If flags were overwritten between authorization and execution, the backend sees the attacker's flags.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • packagekit

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 73 mentions across 24 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 17 signals
  • Patch or workaround mentioned in 16 signals
  • Technical details provided in 52 signals
  • Disclosure: 36 classified signals
  • General: 9 classified signals
  • Peaked 18d ago at 14 mentions (2026-04-27); latest day: 1
  • 73 total mentions across 24 days

Affected systems

Products
packagekit

Deep dive

Activity timeline73 mentions / 24d
0471114Mentions · 2026-04-22: 6Mentions · 2026-04-23: 8Mentions · 2026-04-24: 10Mentions · 2026-04-25: 9Mentions · 2026-04-26: 2Mentions · 2026-04-27: 14Mentions · 2026-04-28: 4Mentions · 2026-04-29: 1Mentions · 2026-05-01: 1Mentions · 2026-05-04: 1Mentions · 2026-05-05: 2Mentions · 2026-05-06: 1Mentions · 2026-05-07: 1Mentions · 2026-05-14: 1Mentions · 2026-05-18: 2Mentions · 2026-05-19: 1Mentions · 2026-05-22: 2Mentions · 2026-05-26: 1Mentions · 2026-06-04: 1Mentions · 2026-06-15: 1Mentions · 2026-06-16: 1Mentions · 2026-06-26: 1Mentions · 2026-07-02: 1Mentions · 2026-09-10: 1PoC Mentioned / Linked · 2026-04-22: 2PoC Mentioned / Linked · 2026-04-23: 7PoC Mentioned / Linked · 2026-04-24: 1PoC Mentioned / Linked · 2026-04-25: 2PoC Mentioned / Linked · 2026-04-26: 1PoC Mentioned / Linked · 2026-04-28: 1PoC Mentioned / Linked · 2026-05-06: 1PoC Mentioned / Linked · 2026-05-19: 1PoC Mentioned / Linked · 2026-06-16: 1Exploit Tool / Code · 2026-04-23: 2Exploit Tool / Code · 2026-04-25: 2Exploit Tool / Code · 2026-04-26: 1Exploit Tool / Code · 2026-06-16: 1Active Exploitation · 2026-04-26: 1Active Exploitation · 2026-04-27: 1Active Exploitation · 2026-09-10: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-04-23: 1Patch / Workaround · 2026-04-24: 3Patch / Workaround · 2026-04-25: 5Patch / Workaround · 2026-04-27: 2Patch / Workaround · 2026-04-28: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-19: 1Technical Details · 2026-04-22: 3Technical Details · 2026-04-23: 7Technical Details · 2026-04-24: 7Technical Details · 2026-04-25: 6Technical Details · 2026-04-26: 1Technical Details · 2026-04-27: 12Technical Details · 2026-04-28: 2Technical Details · 2026-05-04: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-18: 1Technical Details · 2026-05-19: 1Technical Details · 2026-05-22: 2Technical Details · 2026-05-26: 1Technical Details · 2026-06-04: 1Technical Details · 2026-06-15: 1Technical Details · 2026-06-26: 1Technical Details · 2026-07-02: 1Technical Details · 2026-09-10: 104-2204-2404-2604-2805-0105-0505-0705-1805-2206-0406-1607-0209-10
Signal classification6 categories
Disclosure
3649.3%
Patch
1317.8%
General
912.3%
PoC
79.6%
Exploit
68.2%
Active Exploitation
22.7%
Referenced assets42 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-226
Disclosure4Patch1PoC1
2026-04-238
Disclosure3Exploit1Patch1PoC3
2026-04-2410
Disclosure5General1Patch3PoC1
2026-04-259
Disclosure3Exploit2General1Patch3
2026-04-262
Disclosure1Exploit1
2026-04-2714
Active Exploitation1Disclosure9General3Patch1
2026-04-284
Disclosure2Patch1PoC1
2026-04-291
Disclosure1
2026-05-011
General1
2026-05-041
Patch1
2026-05-052
Disclosure1Patch1
2026-05-061
PoC1
2026-05-071
Disclosure1
2026-05-141
General1
2026-05-182
Disclosure1General1
2026-05-191
Patch1
2026-05-222
Disclosure2
2026-05-261
Exploit1
2026-06-041
Disclosure1
2026-06-151
Disclosure1
2026-06-161
Exploit1
2026-06-261
General1
2026-07-021
Disclosure1
2026-09-101
Active Exploitation1
Full discourse20 posts
  • Vozec@Vozec1
    PoC

    I just POC Pack2TheRoot (CVE-2026-41651) : - https://github.com/Vozec/CVE-2026-41651 Local Privilege Escalation in PackageKit discovered by http://telekom.com affecting Ubuntu/Debian/RockyLinux/Fedora https://t.co/VlJKf9Y9LH

    Post summary

    The tweet shares a proof‑of‑concept for CVE-2026-41651, revealing a local privilege escalation flaw in PackageKit across multiple Linux distributions.

    375132814720.0K
    878 followersView on X
  • Aircorridor@_aircorridor
    General

    Privilege Escalation: Getting Started with the Pack2TheRoot (CVE-2026-41651) Vulnerability to Escalate Privileges In this article, we will explore how this vulnerability appears, how it can be exploited, and how you can defend against it. https://hackers-arise.com/privilege-escalation-getting-started-with-the-pack2theroot-cve-2026-41651-vulnerability-to-escalate-privileges/ @three_cube https://t.co/e8M6qAat7n

    Post summary

    The blog post offers a high‑level overview of CVE‑2026‑41651, outlining potential exploitation and general defense strategies, but it lacks detailed technical data, PoC links, or evidence of active attacks.

    353126415216.1K
    13.2K followersView on X
  • SoyITPro@SoyITPro
    Disclosure

    🚨 Nueva vulnerabilidad crítica en Linux El fallo Pack2TheRoot (CVE-2026-41651) afecta a PackageKit y permite a usuarios locales obtener permisos root. 👉 Presente desde 2014 en múltiples distros (Ubuntu, Debian, Fedora, RockyLinux). https://t.co/8JQ1p3J8ep

    Post summary

    A new local privilege escalation vulnerability (CVE‑2026‑41651) in PackageKit allows local users to gain root access, and has been present since 2014 across multiple Linux distributions.

    74211687410.5K
    12.7K followersView on X
  • Cyber Security News@The_Cyber_News
    Disclosure

    ⚠️ Pack2TheRoot Vulnerability Let Attackers Gain Root Access or Compromise the System Source: https://cybersecuritynews.com/pack2theroot-vulnerability/ A high-severity privilege escalation vulnerability, dubbed Pack2TheRoot (CVE-2026-41651, CVSS 3.1: 8.8), has been publicly disclosed. The flaw allows any local unprivileged user to silently install or remove system packages, ultimately achieving full root access without requiring a password. The vulnerability resides in the PackageKit daemon, a widely deployed cross-distribution package management abstraction layer used across Debian, Ubuntu, Fedora, and Red Hat-based systems. Exploiting this flaw, an attacker with basic local access can bypass authorization controls entirely, installing malicious packages or removing critical security components to compromise the system. #cybersecuritynews #Linux

    Post summary

    The article announces CVE‑2026‑41651, a high‑severity privilege escalation flaw in PackageKit that lets local users gain root access, yet it offers no PoC, exploit code, evidence of active exploitation, or patch information.

    4482160389.7K
    67.1K followersView on X
  • Aircorridor@_aircorridor
    PoC

    Privilege Escalation: Exploiting Pack2TheRoot (CVE-2026-41651) See how a trusted package check can be turned into a privilege escalation path by replacing it with a malicious payload at the perfect moment. https://hackers-arise.com/privilege-escalation-getting-started-with-the-pack2theroot-cve-2026-41651-vulnerability-to-escalate-privileges/ @three_cube @DI0256 https://t.co/YJzuz4WHkm

    Post summary

    The post demonstrates how to exploit a privileged escalation via Pack2TheRoot by swapping a trusted package check with malware, linking to a blog that likely contains a PoC, but it does not mention active exploitation, patches, or a playback of an exploit tool.

    1301127796.7K
    13.2K followersView on X
  • kl_secservices@kl_secservices
    Disclosure

    Recent TOCTOU vulnerability in PackageKit allows attackers to escalate privileges to root. The vulnerability, Pack2TheRoot (CVE-2026-41651), is analyzed by our colleague Vadim, who also explains how to protect yourself. Read more: https://purpleshift.io/purple/2026-06-09-rsgr/ https://t.co/9Jl9gEDTgt

    Post summary

    A brief announcement of a new TOCTOU privilege‑escalation vulnerability in PackageKit (CVE‑2026‑41651) with a link to a discussion that offers protection advice, but no exploit code or patch details are provided.

    0430135599.6K
    524 followersView on X
  • Aircorridor@_aircorridor
    General

    Getting Started with the Pack2TheRoot (CVE-2026-41651) Vulnerability to Escalate Privileges Pack2TheRoot is a security flaw that allows unprivileged users to gain full root access on Linux systems via the PackageKit service. Details below: https://hackers-arise.com/privilege-escalation-getting-started-with-the-pack2theroot-cve-2026-41651-vulnerability-to-escalate-privileges/ @three_cube https://t.co/If5wTpMua8

    Post summary

    The tweet introduces the Pack2TheRoot flaw (CVE‑2026‑41651), noting that it allows unauthenticated users to gain root access through the PackageKit service. No PoC, exploit code, active exploitation, or patch information is provided.

    1230134636.9K
    13.5K followersView on X
  • kevops@kevvOH_
    Active Exploitation

    Apparently, one of our test servers was compromised through CVE-2026-41651, a React 2 shell that gave the attacker a reverse shell. At first, it looked like a straightforward compromise. Then we found a reverse shell running as forge since Aug 7, connecting to 77.93.153.91:8080. The forge account was already authorized for unrestricted, passwordless sudo via the server's sudoers configuration. The attacker leveraged that existing privilege to escalate from forge to root with sudo su just 11 minutes later. That root shell is still alive. Then it got more interesting. A root implant, /usr/bin/defaults, had been running since Aug 8, disguised as [php-fpm], with an outbound connection to 167.71.214.178:443. It persisted through server-security.service with Restart=always and was enabled at boot. And our diagnostic tools were lying to us. The attacker had replaced ps, lsof, and netstat with wrappers that filtered their own processes from the output. .bash_history was also wiped. They even modified PHP's disable_functions shortly after installing the root implant to prevent other attackers and webshells from gaining a control. The server was isolated, and fortunately it was a VM. So rather than trust a compromised system, we rebuilt it from a clean image. The persistence and level of stealth were honestly impressive.

    Post summary

    A test server was compromised via CVE‑2026‑41651, enabling a reverse shell and subsequent stealthy root persistence. The post documents a concrete, active exploitation incident rather than a simple disclosure or patch notice.

    9231124394.0K
    16.9K followersView on X
  • Deutsche Telekom CERT@DTCERT
    Disclosure

    🚨 Our Red Team discovered a new Linux vulnerability: “Pack2TheRoot” (CVE-2026-41651) It affects PackageKit versions 1.0.2–1.3.4 across major distros like Ubuntu, Debian, Fedora & Rocky Linux -potentially impacting servers running Cockpit. Details 👇https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html

    Post summary

    A Red Team has disclosed CVE-2026-41651, a local privilege escalation flaw in PackageKit versions 1.0.2–1.3.4 affecting multiple Linux distributions, with detailed information linked for further review.

    227074329.0K
    5.2K followersView on X
  • Co11ateral@co11ateral
    Exploit

    Pack2TheRoot - CVE-2026-41651 TOCTOU race in PackageKit's transaction handler. Any local unprivileged user can install arbitrary packages as root with no authentication If your system has PackageKit (which almost every modern Ubuntu/Fedora/Debian desktop and many servers do) it’s vulnerable out of the box Repo: https://github.com/Vozec/CVE-2026-41651 Research: https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html #cybersecurity #linux

    Post summary

    CVE‑2026‑41651 is a local privilege‑escalation vulnerability in PackageKit, now publicly documented with a functional PoC that allows unprivileged users to install packages as root without authentication.

    110082285.0K
    8.4K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    🚨Claude Opus اكتشف ثغرة عمرها 12 سنة في انظمه لينكس الثغرة في (PackageKit) وتعطي المهاجم صلاحيات Root على النظام. رقم الثغرة: CVE-2026-41651 | التقييم: 8.8 (High). التفاصيل التقنية في التغريدات التالية : 🧵👇

    Post summary

    The tweet announces a 12‑year‑old vulnerability in PackageKit that grants attackers root access, providing the CVE ID and severity score but no evidence of exploitation or mitigation.

    241654510.3K
    49.3K followersView on X
  • Robert Giczewski@lazy_daemon
    PoC

    This is what happens when you give our Red Team a bit of free time to do some research.. #CVE-2026-41651 https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html

    Post summary

    The post highlights that the Red Team has released a proof‑of‑concept for CVE‑2026‑41651, with a link presumably containing the PoC code, but does not include exploitation details, active exploitation reports, or patch information.

    014152305.1K
    770 followersView on X
  • Dark Web Intelligence@DailyDarkWeb
    Patch

    🐧 New Linux Privilege Escalation Vulnerability Discovered A newly disclosed vulnerability in PackageKit (CVE-2026-41651) allows local users to gain root privileges under certain conditions. The issue, dubbed “Pack2TheRoot,” affects multiple Linux distributions where PackageKit is enabled by default. Key points: CVSS score: 8.8 (High) Impacts package management operations Can allow unauthorized installation of system packages The flaw reportedly existed for years before being identified and patched. ⚠️ Organizations running Linux systems should ensure PackageKit is updated to the latest version. #CyberSecurity #Linux #Vulnerability #ThreatIntel

    Post summary

    A new package‑level privilege escalation vulnerability (CVE-2026-41651) is disclosed with a high CVSS score, and organizations are urged to update PackageKit to mitigate the risk.

    117059196.7K
    194.4K followersView on X
  • Aircorridor@_aircorridor
    Exploit

    Privilege Escalation: Getting Started with the Pack2TheRoot (CVE-2026-41651) Vulnerability Recently, we broke down the core mechanics of memory corruption and how you can abuse this vulnerability during cyber operations to take full control of the OS! https://hackers-arise.com/privilege-escalation-getting-started-with-the-pack2theroot-cve-2026-41651-vulnerability-to-escalate-privileges/ @three_cube

    Post summary

    The article explains how CVE‑2026‑41651 can be abused through memory corruption to gain OS control, but it does not provide a functional exploit, patch, or evidence of in‑the‑wild usage.

    114145202.3K
    13.3K followersView on X
  • elhacker.NET@elhackernet
    Disclosure

    Un error de 12 años en Pack2TheRoot permite a usuarios de Linux obtener privilegios de root Un fallo de seguridad llamado Pack2TheRoot , identificado como CVE-2026-41651 (con una puntuación CVSS de 8.8 ) https://blog.elhacker.net/2026/04/un-error-de-12-anos-en-pack2theroot.html

    Post summary

    Se anuncia el fallo CVE-2026-41651 con CVSS 8.8 que permite elevar privilegios en Linux a través de Pack2TheRoot, sin indicación de explotación activa ni PoC.

    1903562.3K
    140.9K followersView on X
  • Nicolas Krassas@Dinosn
    Exploit

    CTF-style Docker lab for CVE-2026-41651 - like vulnerabiities (Pack2TheRoot): PackageKit permissive-polkit local privilege escalation (Exploit at docs/solution.md) https://github.com/dinosn/pack2theroot-lab/tree/main

    Post summary

    The post announces a CTF-style Docker lab for CVE-2026-41651, providing a GitHub repository with exploit code and a solution grid that documents a local privilege escalation through PackageKit's permissive polkit.

    01001871.8K
    158.1K followersView on X
  • portbuster@portbuster1337
    Exploit

    Added CVE-2026-41651 (Pack2TheRoot) to lpe-toolkit: https://github.com/portbuster1337/lpe-toolkit/commit/f20945ee2a4cbcc1317dd9e799e18147fadda876

    Post summary

    The commit adds CVE‑2026‑41651 (Pack2TheRoot) to the lpe-toolkit, indicating that exploit code enabling local privilege escalation is now available.

    06017101.9K
    210 followersView on X
  • Hunt.io@Huntio
    Disclosure

    🚩12-Year-Old PackageKit Flaw Allows Local Users to Gain Root Access https://securityaffairs.com/191231/security/12-year-old-pack2theroot-bug-lets-linux-users-gain-root-privileges.html A 12-year-old PackageKit flaw, now tracked as CVE-2026-41651, can let a local unprivileged Linux user gain root access. The bug, called Pack2TheRoot, affects PackageKit versions 1.0.2 through 1.3.4 and has been seen across multiple distros, including Ubuntu, Debian, Fedora, and Rocky Linux. The fix is in PackageKit 1.3.5, but distro patches may vary. Check if PackageKit is installed on your system and update it if necessary. #Linux #Cybersecurity #InfoSec #PackageKit

    Post summary

    A long‑existing local privilege‑escalation flaw in PackageKit (CVE‑2026‑41651) allows unprivileged Linux users to gain root. The fix resides in PackageKit 1.3.5, so users should update or apply distro patches.

    1501972.2K
    6.5K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    The critical "Pack2TheRoot" flaw (CVE-2026-41651) in PackageKit gives root access on Linux. It went undetected for 12 years. Update to version 1.3.5 now! #Pack2TheRoot #LinuxSecurity #InfoSec #CyberSecurity #CVE202641651 #RootAccess #TechAlert https://securityonline.info/pack2theroot-packagekit-vulnerability-linux-root-exploit/ https://t.co/MCH13gHBWK

    Post summary

    The tweet announces a critical root‑access flaw in PackageKit (CVE-2026-41651), urges users to update to version 1.3.5, and includes a link for more details.

    1401681.3K
    12.5K followersView on X
  • Clandestine@akaclandestine
    PoC

    GitHub - Vozec/CVE-2026-41651 · GitHub https://github.com/Vozec/CVE-2026-41651

    Post summary

    The GitHub repository appears to host a PoC for CVE‑2026‑41651; no evidence of active exploitation, patch, or technical details is provided in the text.

    0401771.5K
    62.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppackagekit_projectpackagekit---

Explore more