QSearchQSearch

CVE-2026-10294

4.3 MEDIUM

A vulnerability has been found in PackageKit up to 1.3.5

Published: 2026-06-01 · Last updated: 2026-06-02

Severity and scoring

CVSS
4.3 MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE
CWE-266, CWE-285

Description

A vulnerability has been found in PackageKit up to 1.3.5. Affected is the function g_file_test of the file src/pk-transaction.c of the component API. Such manipulation of the argument frontend-socket leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-12217 A security vulnerability has been detected in DVDFab Virtual Drive 2.0.0.5 (7.8 HIGH)
  • CVE-2026-12213 A vulnerability was found in hcengineering Huly Platform up to 0.7.0 (4.3 MEDIUM)
  • CVE-2026-12212 A vulnerability has been found in hcengineering Huly Platform up to 0.7.0 (4.3 MEDIUM)
  • CVE-2026-12204 A vulnerability was determined in ShopXO up to 6.7.1 (7.3 HIGH)
  • CVE-2026-12201 A flaw has been found in IObit Malware Fighter up to 13.2.0 (5.3 MEDIUM)