Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»New ‘Pack2TheRoot’ flaw gives hackers root Linux access
    Cybersecurity

    New ‘Pack2TheRoot’ flaw gives hackers root Linux access

    adminBy adminApril 26, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    New ‘Pack2TheRoot’ flaw gives hackers root Linux access
    Share
    Facebook Twitter LinkedIn Pinterest Email

    New ‘Pack2TheRoot’ flaw gives hackers root Linux access

    A new vulnerability dubbed Pack2TheRoot could be exploited in the PackageKit daemon to allow local Linux users to install or remove system packages and gain root permissions.

    The flaw is identified as CVE-2026-41651 and received a high-severity rating of 8.8 out of 10. It has persisted for almost 12 years in the PackageKit daemon, a background service that manages software installation, updates, and removal across Linux systems.

    Earlier this week, some information about the vulnerability has been published, along with PackageKit version 1.3.5 that addresses the issue. However, technical details and a demo exploit have been not been disclosed to allow the patches to propagate.

    image

    An investigation from the Deutsche Telekom Red Team uncovered that the cause of the bug is the mechanism PackageKit uses to handle package management requests.

    Specifically, the researchers found that commands like ‘pkcon install’ could execute without requiring authentication under certain conditions on a Fedora system, allowing them to install a system package.

    Using the Claude Opus AI tool, they further explored the potential for exploiting this behavior and discovered CVE-2026-41651.

    Redacted PoC exploit for Pack2TheRoot
    Redacted PoC exploit for Pack2TheRoot
    Source: Deutsche Telekom

    Impact and fixes

    Deutsche Telekom’s Red Team reported their findings to Red Hat and PackageKit maintainers on April 8. They state that it’s safe to assume that all distributions that come with PackageKit pre-installed and enabled out-of-the-box are vulnerable to CVE-2026-41651.

    The vulnerability has been present in PackageKit version 1.0.2, released in November 2014, and affects all versions through 1.3.4, according to the project’s security advisory.

    Researchers’ testing have confirmed that an attacker could exploit the the CVE-2026-41651 vulnerability in the following Linux distributions:

    • Ubuntu Desktop 18.04 (EOL), 24.04.4 (LTS), 26.04 (LTS beta)
    • Ubuntu Server 22.04 – 24.04 (LTS)
    • Debian Desktop Trixie 13.4
    • RockyLinux Desktop 10.1
    • Fedora 43 Desktop
    • Fedora 43 Server

    The list is not exhaustive, though, and any Linux distribution using PackageKit should be treated as potentially vulnerable to attacks.

    Users should upgrade to PackageKit version 1.3.5 as soon as possible, and ensure that any other software using the package as a dependency has been moved to a safe release.

    Users can use the commands below to check if they have a vulnerable version of the PackageKit installed and if the daemon is running:

    dpkg -l | grep -i packagekit

    rpm -qa | grep -i packagekit

    Users can run systemctl status packagekit or pkmon to check if the PackageKit daemon is available and running, which indicates that the system may be at risk if left unpatched.

    Although no details about the state of exploitation have been shared, the researchers noted that there are strong signs showing compromise because exploitation leads to the PackageKit daemon hitting an assertion failure and crashing.

    Even if systemd recovers the daemon, the crash is observable in the system logs.


    article image

    AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.

    At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what’s exploitable, proves controls hold, and closes the remediation loop.

    Claim Your Spot

    access Flaw hackers Linux Pack2TheRoot root
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleCopperhelm Raises $7 Million for Agentic Cloud Security Platform
    Next Article Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach
    admin
    • Website

    Related Posts

    Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach

    April 26, 2026

    Copperhelm Raises $7 Million for Agentic Cloud Security Platform

    April 26, 2026

    AI is speeding up nation-state cyber programs

    April 26, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach

    April 26, 2026

    New ‘Pack2TheRoot’ flaw gives hackers root Linux access

    April 26, 2026

    Copperhelm Raises $7 Million for Agentic Cloud Security Platform

    April 26, 2026

    AI Overview CTR Fell 61%, But Clicks Didn’t Collapse

    April 26, 2026
    Categories
    • Blogging (68)
    • Cybersecurity (1,523)
    • Privacy & Online Earning (183)
    • SEO & Digital Marketing (929)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (246)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach

    April 26, 2026

    New ‘Pack2TheRoot’ flaw gives hackers root Linux access

    April 26, 2026

    Copperhelm Raises $7 Million for Agentic Cloud Security Platform

    April 26, 2026
    Most Popular
    • Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach
    • New ‘Pack2TheRoot’ flaw gives hackers root Linux access
    • Copperhelm Raises $7 Million for Agentic Cloud Security Platform
    • AI Overview CTR Fell 61%, But Clicks Didn’t Collapse
    • AI is speeding up nation-state cyber programs
    • Microsoft to roll out Entra passkeys on Windows in late April
    • Bitwarden NPM Package Hit in Supply Chain Attack
    • Beating Automated Exploitation at AI Speed
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.