A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role == REPO_REMOVE || !SIMULATE), which is always true for RepoRemove. An unprivileged local user can therefore perform a genuine package uninstall while claiming to simulate. This vulnerability only affects systems using PackageKit with the dnf5 backend.
{
"cna_assigner": "fedora",
"cwe_ids": [
"CWE-863"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19816.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19816.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "270461123028998288870474421320959343379",
"length": 7840
},
"id": "CVE-2026-19816-2848a412",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/packagekit/packagekit/commit/33be77b3ecd3b566ca117358dc18c58c964e627b",
"target": {
"file": "backends/dnf5/dnf5-backend-thread.cpp",
"function": "dnf5_transaction_thread"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"171237454910942151134272633908483188324",
"208416502006613427203470661593680397330",
"83666962922781040001010884852185290866",
"90932504323604005399669864871396355657",
"335388204447370313008434221149743623782",
"30164295831447238112819618187149215760",
"254045841424264766247508436798178675801",
"324968928179143455818430726602944587431",
"222440860946810283281804467182168602197",
"100143797007324273795077498666700964366",
"234143384742276132942246197973849405087",
"77695068122427647746603121581344597807",
"184624696468649856029688835192856030239",
"134852853111390111794371945387457642293",
"328174982379127202173274759680312670060",
"218853539589914721521657881344217322481",
"176401807287483131812586819056612135187",
"338694414875352571591346238338062360946",
"288450575237033810204090069390314985777",
"274450393798501509621806252133888604656",
"17703789391370130476328287686713731120",
"338848011217005578756057327466152662828",
"288450575237033810204090069390314985777",
"274450393798501509621806252133888604656",
"17703789391370130476328287686713731120",
"19326727229521545158549323745366388388",
"149023440095359658286255476541907046350",
"297009935371518550487640813362384143434",
"126773478233768570645783975351830765637",
"293575060895465527674987426541805731749",
"110135528444295677486946581880276817356",
"16164951993528750913922288026426937592",
"326220248040233455152114439103971540684",
"163293596709540279957772978136503361131",
"86306514190786929730290436894438998373",
"288756151529357593617608017355081619103",
"110962691690873480608723074962369142902",
"249618183166741635444167739460125473251",
"138288281903682535794609863300078133866",
"302520314919158518878094909828121814020",
"87088447637569863349722039763094747787",
"74928828692898101291055364743242867150",
"59633921447959060914154758107474561051",
"211253111680599717396393146714783760716",
"198608529642377323803428883777543760696",
"79007256589712313630067021520054716170",
"51026617011380588040406385122297507866",
"278359482300257932943327063279284818256",
"236402903464329132328598708708093495064",
"24905583221533528761884902673305787189",
"29854917536281460153902166376024162984",
"250591168648629658674386286999368127372",
"161657740799757150516000513883657973027",
"98662990057714094859427379470999646918",
"24494627877179952498992217435857170738",
"266718837321299002518978140756310204159",
"330255126197451653313412075739557392970",
"147976990335538555198451732370584810690"
],
"threshold": 0.9
},
"id": "CVE-2026-19816-36053575",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/packagekit/packagekit/commit/33be77b3ecd3b566ca117358dc18c58c964e627b",
"target": {
"file": "backends/dnf5/dnf5-backend-thread.cpp"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "307478140725154941899769849548852032538",
"length": 5338
},
"id": "CVE-2026-19816-629cd7d0",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/packagekit/packagekit/commit/33be77b3ecd3b566ca117358dc18c58c964e627b",
"target": {
"file": "backends/dnf5/dnf5-backend-thread.cpp",
"function": "dnf5_repo_thread"
}
}
]
"2026-09-20T14:24:40Z"