A new vulnerability dubbed Pack2TheRoot could be exploited in the PackageKit daemon to allow local Linux users to install or remove system packages and gain root permissions. The flaw is identified as CVE-2026-41651 and received a high-severity rating of 8.8 out of 10. It has persisted for almost 12 years in the PackageKit daemon, a background service that manages software installation, updates, and removal across Linux systems. Earlier this week, some information about the vulnerability has been published, along with PackageKit version 1.3.5 that addresses the issue. However, technical details and a demo exploit have been not been disclosed to allow the patches to propagate. An investigation from the Deutsche Telekom Red Team uncovered that the cause of the bug is the mechanism PackageKit uses to handle package management requests. Specifically, the researchers found that commands like ‘pkcon install’ could execute without requiring authentication under certain conditions on a Fedora system, allowing them to install a system package. Using the Claude Opus AI tool, they further explored the potential for exploiting this behavior and discovered CVE-2026-41651. Deutsche Telekom's Red Team reported their findings to Red Hat and PackageKit maintainers on April 8. They state that it’s safe to assume that all distributions that come with PackageKit pre-installed and enabled out-of-the-box are vulnerable to CVE-2026-41651. The vulnerability has been present in PackageKit version 1....
New ‘Pack2TheRoot’ flaw gives hackers root Linux access
BleepingComputer
·Bill Toulas
·Published Apr 24, 2026
·Updated
Affected Software
1 affected component
PackageKit daemon>=1.0.2<=1.3.4
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a new vulnerability named Pack2TheRoot that affects the PackageKit daemon and allows hackers to gain root access on Linux systems.
2
What security implications are discussed?
The vulnerability permits local users to install or remove system packages and escalate their permissions to root, posing a significant security risk.
3
What products or software are affected?
The affected software is the PackageKit daemon, specifically versions between 1.0.2 and 1.3.4.
4
What is the identifier associated with the Pack2TheRoot flaw?
The vulnerability is identified as CVE-2026-41651.
5
Who is at risk due to this vulnerability?
Local users of affected Linux systems are at risk of exploiting this flaw to gain unauthorized root access.