CVE-2026-10294
MEDIUM
NVD
CVSS Score
4.3
Severity
MEDIUM
Published
Jun 01, 2026
Vendor
unknown
Description
A vulnerability has been found in PackageKit up to 1.3.5. Affected is the function g_file_test of the file src/pk-transaction.c of the component API. Such manipulation of the argument frontend-socket leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.